PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter.
- https://www.exploit-db.com/exploits/4520
- https://github.com/rnbochsr/yr_of_the_jellyfish