prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phplib | Phplib_team | 7.2 | 7.2 |
Phplib | Phplib_team | 7.2.1 | 7.2.1 |
Phplib | Phplib_team | 7.2b | 7.2b |
Phplib | Phplib_team | 7.2c | 7.2c |