PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.
https://github.com/arkede/cve-2003
https://exchange.xforce.ibmcloud.com/vulnerabilities/12205
https://euvd.enisa.europa.eu/vulnerability/EUVD-2003-1589
http://www.securityfocus.com/bid/7785
http://www.openwall.com/lists/oss-security/2012/01/06/3
http://www.kernelpanik.org/docs/kernelpanik/wordpressadv.txt