CVE-2008-6074
06.02.2009, 11:30
Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the importFunction parameter.
Vendor | Product | Version |
---|---|---|
phpcrs | phpcrs | 𝑥 ≤ 2.06 |
phpcrs | phpcrs | 1.01 |
phpcrs | phpcrs | 2.00 |
phpcrs | phpcrs | 2.01 |
phpcrs | phpcrs | 2.02 |
phpcrs | phpcrs | 2.03 |
phpcrs | phpcrs | 2.04 |
phpcrs | phpcrs | 2.05 |
𝑥
= Vulnerable software versions
References