Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) addons/plugin.php, (2) addons/sidebar.php, (3) mail/index.php, or (4) mail/mailbox.php in modules/.
- http://securityreason.com/securityalert/3116
- https://www.exploit-db.com/exploits/4381
- https://github.com/ARPSyndicate/cve-scores