Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter. NOTE: some of these details are obtained from third party information. Hyperlink Record 1058675 indicates:
"Successful exploitation of the vulnerability for executing arbitrary uploaded PHP code requires valid user credentials."
Publication date: Fri, 20 Feb 2009 07:30:00 +0000