Heap
01-07-09, 02:50
PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the pathtoserverdata parameter. NOTE: the installation instructions specify deleting the install/ folder.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2262)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2262)