Tagger LE Multiple PHP Code Injection Vulnerabilities

Tagger LE is prone to multiple PHP code-injection vulnerabilities that may allow remote attackers to inject arbitrary PHP code into scripts.

If the attacker is successful, the attacker-supplied code will run in a PHP 'eval()' function call with the privileges of the server process.

A successful attack may result in unauthorized access in the context of the server.


 

Privacy Statement
Copyright 2010, SecurityFocus