Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDEPATH] parameter to (1) simpleuser/pages/index.inc.php and (2) stats/pages/index.inc.php.
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDEPATH] parameter to imageresize/pages/index.inc.php.