PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (coma6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfiglivesite parameter. NOTE: some of these details are obtained from third party information.