PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the _settings[pluginpath] parameter.Referenceshttp://www.securityfocus.com/bid/29877https://www.exploit-db.com/exploits/5902/https://exchange.xforce.ibmcloud.com/vulnerabilities/43251