PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Korweblog | Korweblog | 1.6.1 (including) | 1.6.1 (including) |
Korweblog | Korweblog | 1.6.2cvs (including) | 1.6.2cvs (including) |