Description
PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Affected products
- adam_van_dongen / com_forum1.2.4rc3 – 1.2.4rc3
- adam_van_dongen / phpbb_component1.2.4rc3 – 1.2.4rc3