Launchpad.net

CVE 2006-3964

PHP remote file inclusion vulnerability in members.php in Banex PHP MySQL Banner Exchange 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_root parameter.

See the CVE page on Mitre.org for more details.

References