PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24989
http://www.securityfocus.com/archive/1/426214/100/0/threaded