PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter. Successful exploitation requires that "register_globals" is enabled.
Publication date: Fri, 22 Jun 2007 23:30:00 +0000