PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.Referenceshttp://firestats.cc/wiki/ChangeLog#a1.6.2-stable13062009http://secunia.com/advisories/35400https://www.exploit-db.com/exploits/8945