PHP remote file inclusion vulnerability in php4you.php in PHPIrc_bot 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE, since the dir variable is declared before being used
https://exchange.xforce.ibmcloud.com/vulnerabilities/31185
http://www.securityfocus.com/archive/1/455613/100/0/threaded