PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter. Successful exploitation requires that "register_globals" is enabled.
Publication date: Mon, 18 Dec 2006 17:28:00 +0000