CVE-2007-5097 | Online Fantasy Football League offl 0.2.6 offl_nflteam.php DOC_ROOT code injection (OSVDB-38722)
A vulnerability, which was classified as critical, was found in Online Fantasy Football League offl 0.2.6. Affected is an unknown function in the library lib/classes/offl_nflteam.php of the file offl_nflteam.php. The manipulation of the argument DOC_ROOT leads to code injection.
This vulnerability is traded as CVE-2007-5097. It is possible to launch the attack remotely. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.