objects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to malicious code on an attacker-controlled web site.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Blnews | Blnews | 2.1.3 (including) | 2.1.3 (including) |