CVE-2006-4713
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
Date published : 2006-09-12
http://www.securityfocus.com/bid/19940
http://www.securityfocus.com/archive/1/445723/100/0/threaded