CVE-2007-2328
PHP remote file inclusion vulnerability in addvip.php in phpMYTGP 1.4b allows remote attackers to execute arbitrary PHP code via a URL in the msetstr[PROGSDIR] parameter.
Date published : 2007-04-26
http://www.securityfocus.com/archive/1/466845/100/0/threaded