PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter. Successful exploitation requires that "register_globals" is enabled.
Publication date: Wed, 27 Jun 2007 05:30:00 +0000