PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8705
Reference (s):
- http://rossmarks.uk/portfolio.php
- http://rossmarks.uk/whitepapers/wonder_cms_2014.txt

