CVE-2006-2872
PHP remote file inclusion vulnerability in config.php in Rumble 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the configArr[pathtodir] parameter.
Date published : 2006-06-06
http://www.securityfocus.com/archive/1/435974/100/0/threaded