PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. The vendor has released version 1.3 to address this issue.
Publication date: Sat, 02 Sep 2006 04:04:00 +0000