PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WN_BASEDIR parameter.
| Software | From | Fixed in |
|---|---|---|
| netwin / webnews | 1.1i | 1.1i.x |
| netwin / webnews | 1.4 | 1.4.x |
| netwin / webnews | 1.1h | 1.1h.x |
| netwin / webnews | 1.1j | 1.1j.x |
| netwin / webnews | 1.1k | 1.1k.x |