Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Silver

#37772of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2008-3698
7.5
2008-05-14
Scorpnews · Scorpnews · CVE-2008-2193
**Name of the Vulnerable Software and Affected Versions** ScorpNews version 2.0 **Description** A remote file inclusion issue in example.php allows remote attackers to execute arbitrary PHP code via a URL in the `site` parameter. **Recommendations** For ScorpNews version 2.0, consider disabling the `example.php` file or restricting access to it until a patch is available. Avoid using the `site` parameter in the affected endpoint until the issue is resolved.