PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP code via a URL in the path_pre parameter.Referenceshttp://www.gentoo.org/security/en/glsa/glsa-200412-27.xmlhttp://secunia.com/advisories/13660http://www.osvdb.org/12613http://www.securityfocus.com/bid/12116http://securitytracker.com/id?1012708http://www.phprojekt.com/modules.php?op=modload&name=News&file=article&sid=193https://exchange.xforce.ibmcloud.com/vulnerabilities/18683