Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noahs Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Noahs_classifieds | Phpoutsourcing | 1.2 (including) | 1.2 (including) |
| Noahs_classifieds | Phpoutsourcing | 1.3 (including) | 1.3 (including) |