CVE-2006-0854
PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used.
Date published : 2006-02-22
http://www.securityfocus.com/bid/16787
http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0339.html