CVE-2009-3660
11.10.2009, 22:30
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.
Vendor | Product | Version |
---|---|---|
efrontlearning | efront | 𝑥 ≤ 3.5.4 |
efrontlearning | efront | 3.1.0 |
efrontlearning | efront | 3.1.2 |
efrontlearning | efront | 3.1.3 |
efrontlearning | efront | 3.1.4 |
efrontlearning | efront | 3.5.0 |
efrontlearning | efront | 3.5.0:beta1 |
efrontlearning | efront | 3.5.0:beta2 |
efrontlearning | efront | 3.5.0:beta3 |
efrontlearning | efront | 3.5.0:beta4 |
efrontlearning | efront | 3.5.1 |
𝑥
= Vulnerable software versions
References