PhpDig version 1.6.x allows for remote command execution in its config.php script. Anybody can inject a url in the relative_script_path variable and obtain command execution with web server privileges.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/32512/phpdig16x.txt
Source: https://packetstormsecurity.com/files/32512/phpdig16x.txt.html

