CVE-2010-1114
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator – Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php.
Date published : 2010-03-25
http://www.securityfocus.com/bid/37841
http://www.packetstormsecurity.com/1001-exploits/webservercreator-traversalxssrfi.txt