VYPR

Phpmyprofiler

by Phpmyprofiler

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2006-51860.040.11Oct 10, 2006PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter.
CVE-2007-51140.000.01Sep 26, 2007PHP remote file inclusion vulnerability in include/plugin/block.t.php in Peter Schmidt phpmyProfiler 0.9.6b allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. NOTE: this issue is disputed by CVE because the applicable require_once is in a function that is not called on a direct request