CVE

Id
17943  
CVE No.
CVE-2006-1839  
Status
Candidate  
Description
PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.  
Phase
Assigned (20060419)  
Votes
None (candidate not yet proposed)  
Comments