PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/26839
http://www.vupen.com/english/advisories/2006/2036
http://www.securityfocus.com/archive/1/435283/100/0/threaded