PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sponge_news | Sponge_news | * | 2.2 (including) |