PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the HTTP_DOCUMENT_ROOT parameter, a different vector than CVE-2006-6689. Successful exploitation requires that "register_globals" is enabled.
This vulnerability is addressed in the following product release:
Paristemi, Paristemi, 0.8.4
Publication date: Wed, 27 Dec 2006 05:28:00 +0000