CVE-2009-4223 | Gianni Tommasi Kr-php Web Content Server up to 1.1 adm/krgourl.php DOCUMENT_ROOT code injection (EDB-10216 / XFDB-54395)
A vulnerability, which was classified as critical, has been found in Gianni Tommasi Kr-php Web Content Server up to 1.1. Affected by this issue is some unknown functionality of the file adm/krgourl.php. The manipulation of the argument DOCUMENT_ROOT leads to code injection.
This vulnerability is handled as CVE-2009-4223. The attack may be launched remotely. Furthermore, there is an exploit available.