CVE-2009-4264: Code Injection
PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when registerglobals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the languagepath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4264?
CVE-2009-4264 is considered to be of high severity due to its potential to allow remote code execution.
How do I fix CVE-2009-4264?
To fix CVE-2009-4264, disable register_globals in your PHP configuration and update AROUNDMe to a version later than 1.1 where the vulnerability is resolved.
What software versions are affected by CVE-2009-4264?
CVE-2009-4264 affects AROUNDMe versions 0.5.1, 0.5.2, 0.6.9, and 0.7.7.
What type of vulnerability is CVE-2009-4264?
CVE-2009-4264 is a PHP remote file inclusion vulnerability that allows arbitrary code execution.
Who can be impacted by CVE-2009-4264?
Any server running the affected versions of AROUNDMe with register_globals enabled is at risk from CVE-2009-4264.