PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.Referenceshttps://www.exploit-db.com/exploits/2659http://secunia.com/advisories/22627http://www.vupen.com/english/advisories/2006/4227http://www.securityfocus.com/bid/20773