Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noahs Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Noahs_classifieds | Phpoutsourcing | 1.2 (including) | 1.2 (including) |
Noahs_classifieds | Phpoutsourcing | 1.3 (including) | 1.3 (including) |