Direct static code injection vulnerability in QLnews 1.2 allows remote authenticated administrators to execute arbitrary PHP code by modifying config.php.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Qlnews |
Vscripts.pl |
1.2 (including) |
1.2 (including) |
References