Secunia Security Advisory – cYon has reported a vulnerability in PHProjekt, which can be exploited by malicious people to compromise a vulnerable system. Input passed to the path_pre parameter in authform.inc.php is not properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/35560/sa13660.txt
Source: https://packetstormsecurity.com/files/35560/Secunia-Security-Advisory-13660.html

