PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/21562
http://www.securityfocus.com/bid/14368
http://securitytracker.com/id?1014569