PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote malicious users to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
php evolution news evolution 1.0 |
||
php evolution news evolution 2.0 |