PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-02-13 17:30
Updated : 2024-02-04 17:33
NVD link : CVE-2009-0572
Mitre link : CVE-2009-0572
CVE.ORG link : CVE-2009-0572
JSON object : View
Products Affected
flatnux
- flatnux
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')