nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.
Score: 0.0
Priority: Unclassified
Score: 0.00587
Percentile:
0.68097
CVSS v2 Score: 5.0
Severity: