Description
PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the language_path parameter.
Affected products
- aroundme / aroundme0.5.1 – 0.5.1
- aroundme / aroundme0.5.2 – 0.5.2
- aroundme / aroundme0.6.9 – 0.6.9
- barnraiser / aroundme1.1
- barnraiser / aroundme0.7.7 – 0.7.7
References
- EXPLOIThttp://www.exploit-db.com/exploits/10329
- VENDOR_ADVISORYhttp://secunia.com/advisories/37567