First published: Wed May 28 2008(Updated: )
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Idefense Comraider | =1.0.7 | |
Idefense Comraider | =1.0.7a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2481 is considered critical due to its ability to allow remote attackers to execute arbitrary PHP code.
To fix CVE-2008-2481, it is recommended to disable register_globals and upgrade to a patched version of phpRaider.
CVE-2008-2481 affects phpRaider versions 1.0.7 and 1.0.7a.
CVE-2008-2481 is a remote file inclusion vulnerability.
CVE-2008-2481 is exploited through the pConfig_auth[phpbb_path] parameter.