PHP remote file inclusion vulnerability in cat_viewed.php in AL-Caricatier 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the CatName parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/35810
http://www.securityfocus.com/archive/1/475641/100/0/threaded