PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-2180
http://www.hardened-php.net/advisory-072005.php