PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the REP_INC parameter.
https://www.exploit-db.com/exploits/2149
https://exchange.xforce.ibmcloud.com/vulnerabilities/28320