PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root parameter.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-3327
http://www.securityfocus.com/bid/15175