PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 83.4%