PHP remote file inclusion vulnerability in login.php in My_REFERER 1.08 allows remote attackers to execute arbitrary PHP code via a URL in the value parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/36148
http://www.securityfocus.com/archive/1/482006/100/0/threaded
http://www.securityfocus.com/archive/1/477253/100/0/threaded
http://securityvulns.com/source26994.html
http://securityvulns.com/source13951.html