CVE
- Id
- 17943
- CVE No.
- CVE-2006-1839
- Status
- Candidate
- Description
- PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.
- Phase
- Assigned (20060419)
- Votes
- None (candidate not yet proposed)
- Comments