PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the sFileName parameter.
https://www.exploit-db.com/exploits/6733
http://www.securityfocus.com/bid/27671
http://www.securityfocus.com/archive/1/487695/100/200/threaded