CVE
- Id
- 33003
- CVE No.
- CVE-2008-2886
- Status
- Candidate
- Description
- PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.
- Phase
- Assigned (20080627)
- Votes
- None (candidate not yet proposed)
- Comments