2006-04-02 21:00:00
mitre
PUBLISHED
Direct static code injection vulnerability in QLnews 1.2 allows remote authenticated administrators to execute arbitrary PHP code by modifying config.php.