Vulnonym.org

CVE-2008-2885 - Far gone Patch

Description

PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODARS) 1.0.2 when register_globals is enabled allows remote attackers to execute arbitrary PHP code via a URL in the CLASSES_ROOT parameter.

Reference

http://secunia.com/advisories/30784 http://www.securityfocus.com/bid/29881 https://exchange.xforce.ibmcloud.com/vulnerabilities/43285 https://www.exploit-db.com/exploits/5906