A vulnerability has been identified in PHP Object Framework (PHPOF), which could be exploited by remote attackers to compromise a vulnerable web server. This issue is caused by an input validation error in the "dbmodules/DB_adodb.class.php" script when processing the "PHPOF_INCLUDE_PATH" parameter, which could be exploited by remote attackers to include malicious PHP scripts and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: PHP Object Framework (PHPOF) version 20040226 and prior