Skip to main content
Loading…
    CVE-2006-3685 — PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath parameter to cn_config.php. NOTE: the news.php vecto — CVE Database · The Intelligence Room