VYPR
Unrated severityNVD Advisory· Published Dec 31, 2002· Updated Apr 16, 2026

CVE-2002-2249

CVE-2002-2249

Description

PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.

Affected products

2
  • cpe:2.3:a:php_evolution:news_evolution:1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:php_evolution:news_evolution:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php_evolution:news_evolution:2.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.