CVE-2006-5931 - Inhuman Effective
Description
Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 when register_globals is enabled allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to certain PHP scripts in (1) lib/actions/ (2) lib/displays/ (3) lib/editforms/ (4) lib/functions/ (5) scheme/ and (6) the root directory. NOTE: the provenance of this information is unknown; details are obtained from third party sources.