CVE-2006-7124
PHP remote file inclusion vulnerability in external/rssfeeds.php in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to execute arbitrary PHP code via the baseDir parameter.
Date published : 2007-03-05
http://www.securityfocus.com/bid/20267
http://www.securityfocus.com/archive/1/447356/100/0/threaded