PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Sponge_news |
Sponge_news |
* |
2.2 (including) |
References