CVE
- Id
- 33356
- CVE No.
- CVE-2008-3239
- Status
- Candidate
- Description
- Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code via a filename in the CONF[CRON_LOGFILE] parameter and file contents in the CONF[LOCALE_LONG_DATE_TIME] parameter.
- Phase
- Assigned (20080721)
- Votes
- None (candidate not yet proposed)
- Comments