PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter. Successful exploitation requires that "register_globals" is enabled and that support for ".htaccess" files is disabled.
Publication date: Wed, 25 Oct 2006 01:07:00 +0000