PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Sponge_news | Sponge_news | * | 2.2 (including) |