PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Wanewsletter |
Wanewsletter |
* |
2.1.3 (including) |
References