Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (comextcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIGEXT[LANGUAGESDIR] parameter to adminevents.php, (2) the mosConfigabsolutepath parameter to extcalendar.php, or (3) the CONFIGEXT[LIBDIR] parameter to lib/mail.inc.php.