PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This vulnerability has a 3.01% probability of being exploited in the next 30 days, ranking higher than 87% of all scored CVEs.