PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18694
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-2593
http://www.ubertec.co.uk/forums/showthread/php?t=2376
http://www.securityfocus.com/bid/12105
http://www.gulftech.org/?node=research&article_id=00058-12242004