CVE-2009-2396 – DM Albums <= 1.9.2 - Remote File Inclusion
https://notcve.org/view.php?id=CVE-2009-2396
PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter. Vulnerabilidad de inclusión de archivo remoto PHP en template/album.php en DM Albums v1.9.2, utilizado independiente o como un plugin de WordPress, permite a atacantes remotos ejecutar código PHP arbitrario a través de una URL en el parámetro SECURITY_FILE. • https://www.exploit-db.com/exploits/9043 http://secunia.com/advisories/35619 http://www.exploit-db.com/exploits/9043 http://www.securityfocus.com/bid/35521 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •