PHP remote file inclusion vulnerability in templates/tmpl_dfl/scripts/index.php in BoonEx Dolphin 5.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter. NOTE: it is possible that this issue overlaps CVE-2006-4189. Successful exploitation requires that "register globals" is enabled and that "magic quotes" is disabled.
Publication date: Fri, 20 Oct 2006 19:07:00 +0000