PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-1441
http://www.gulftech.org/?node=research&article_id=00071-05022005