Vulnerabilities > Sponge News

DATE CVE VULNERABILITY TITLE RISK
2006-09-08 CVE-2006-4647 Remote File Include vulnerability in Sponge News News.PHP
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter.
network
low complexity
sponge-news
7.5