Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter in (1) includes/journalsdelete.php, (2) includes/journalspost.php, or (3) includes/journalsedit.php.