Description
PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.
Affected products
- attachmax / dolphin2.1.0 – 2.1.0
References
- MISChttp://osvdb.org/48269
- MISChttp://e-rdc.org/v1/news.php?readmore=108
- VENDOR_ADVISORYhttp://secunia.com/advisories/31794
- EXPLOIThttps://www.exploit-db.com/exploits/6468
- MISChttp://www.securityfocus.com/archive/1/496427/100/0/threaded
- MISChttp://www.securityfocus.com/bid/31207
- MISChttp://securityreason.com/securityalert/4307