Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.Referenceshttp://securityreason.com/securityalert/3388https://www.exploit-db.com/exploits/4635http://www.securityfocus.com/archive/1/483867/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/38543http://www.securityfocus.com/bid/26481http://www.r57.li/exploit.txt