Multiple PHP remote file inclusion vulnerabilities in awrate 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) 404.php or (2) topbar.php, different vectors than CVE-2006-6368.Referenceshttp://www.securityfocus.com/bid/26336http://arfis.wordpress.com/2007/09/13/rfi-02-awratecom-message-board/http://osvdb.org/45528http://osvdb.org/45529