CVE

Id
37100  
CVE No.
CVE-2008-6983  
Status
Candidate  
Description
modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.  
Phase
Assigned (20090817)  
Votes
None (candidate not yet proposed)  
Comments