PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the ezUserManager_Path parameter to ezusermanager_pwd_forgott.php, possibly due to an issue in ezusermanager_core.inc.php. The vulnerability has been confirmed in version 1.6 and the vendor states that only version 1.6 is affected. Successful exploitation requires that "register_globals" is enabled. A patched version (1.7b) was released 17th May 2006 that fixes this vulnerbility.
Publication date: Wed, 17 May 2006 15:06:00 +0000