PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php. Successful exploitation requires that "register_globals" is enabled.
Publication date: Fri, 31 Dec 2004 11:00:00 +0000