CVE-2006-4488

PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the exbb[home_path] parameter.

Date published : 2006-08-31

http://www.securityfocus.com/bid/19753

http://exbb.clans.it/forum/announcements.php