PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-2199
http://www.securityfocus.com/bid/14208
http://spid.adnx.net/index_en.html#log