PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. Successful exploitation requires that "register_globals" is enabled.
This vulnerability is addressed in the following product update:
phpMyProfiler, phpMyProfiler, 0.9.6b
Publication date: Tue, 10 Oct 2006 09:06:00 +0000