PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri Seitz Security Suite IP Logger 1.0.0 in dwingmods for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
https://www.exploit-db.com/exploits/2480
https://exchange.xforce.ibmcloud.com/vulnerabilities/29321