CVE-2009-4264
10.12.2009, 16:30
PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the language_path parameter.
| Vendor | Product | Version |
|---|---|---|
| aroundme | aroundme | 0.5.1 |
| aroundme | aroundme | 0.5.2 |
| aroundme | aroundme | 0.6.9 |
| barnraiser | aroundme | 𝑥 ≤ 1.1 |
| barnraiser | aroundme | 0.7.7 |
𝑥
= Vulnerable software versions