Scorpnews · Scorpnews · CVE-2008-2193
**Name of the Vulnerable Software and Affected Versions**
ScorpNews version 2.0
**Description**
A remote file inclusion issue in example.php allows remote attackers to execute arbitrary PHP code via a URL in the `site` parameter.
**Recommendations**
For ScorpNews version 2.0, consider disabling the `example.php` file or restricting access to it until a patch is available. Avoid using the `site` parameter in the affected endpoint until the issue is resolved.