PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter.
http://www.vupen.com/english/advisories/2005/2599
http://www.securityfocus.com/archive/1/417796/100/0/threaded