PHP remote file inclusion vulnerability in admin/index.php in Fusion Polls allows remote attackers to execute arbitrary PHP code via a URL in the xtrphome parameter.Referenceshttp://www.securityfocus.com/archive/1/437127/30/4380/threadedhttp://www.securityfocus.com/archive/1/441493/30/4380/threaded