PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary PHP code via a URL in the config[BASE_DIR] parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/28583
http://www.securityfocus.com/archive/1/444416/100/0/threaded