PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Phpnews | Phpnews | 1.2.3 (including) | 1.2.3 (including) |
| Phpnews | Phpnews | 1.2.4 (including) | 1.2.4 (including) |