Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) components/com_minibb.php or (2) components/minibb/index.php.
https://www.exploit-db.com/exploits/2030
https://exchange.xforce.ibmcloud.com/vulnerabilities/27749
http://www.securityfocus.com/bid/18998
http://www.securityfocus.com/archive/1/440132/100/0/threaded
http://securitytracker.com/id?1016507