MEDIUM
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter, a different vector than CVE-2006-2149
Published Feb 23, 2007
6.8
MEDIUMCVSS 2.0
EPSS 4.33%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.