Back

CVE-2002-2249

PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.

Published: Dec 31, 2002 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (2)

Vendor Product Version
php_evolution news_evolution 1.0
php_evolution news_evolution 2.0

GitHub Security Advisory GHSA-63hm-3qvh-mg6x

PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.31%

Top 18% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub