PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP code via a URL in the path_pre parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18683
http://www.securityfocus.com/bid/12116
http://www.phprojekt.com/modules.php?op=modload&name=News&file=article&sid=193
http://www.gentoo.org/security/en/glsa/glsa-200412-27.xml