CVE-2008-2886
27.06.2008, 18:41
PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.
| Vendor | Product | Version |
|---|---|---|
| jamroom | jamroom | 3.3.0 |
| jamroom | jamroom | 3.3.1 |
| jamroom | jamroom | 3.3.2 |
| jamroom | jamroom | 3.3.3 |
| jamroom | jamroom | 3.3.4 |
| jamroom | jamroom | 3.3.5 |
𝑥
= Vulnerable software versions
References