"evaluatorImpact":"Successful exploitation requires that \"register_globals\" is enabled.",
"descriptions":[
{
"lang":"en",
"value":"include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter. NOTE: some of these details are obtained from third party information. It is likely that this issue can be exploited to conduct directory traversal attacks."
},
{
"lang":"es",
"value":"include/debug.php de Webfwlog 0.92 y versiones anteriores cuando register_globals est\u00e1 activado, permite a atacantes remotos obtener c\u00f3digo fuente de ficheros a trav\u00e9s del par\u00e1metro conffile.\r\nNOTA: algunos de estos detalles se han obtenido de informaci\u00f3n de terceros. Es probable que esta vulnerabilidad pueda ser explotada para conseguir ataques de escalado de directorio."