PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Brudanews | Brudaswen | * | 1.1 (including) |