PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lan_management_system | Lms | * | 1.6.9 (including) |