PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute arbitrary PHP code via a URL in the src parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/28497
http://www.securityfocus.com/archive/1/443930/100/0/threaded