Drupal Configuration Vulnerability - CVE-2008-6171
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6 when the server is configured for quotIP-based virtual hostsquot allows remote attackers to include and execute arbitrary files via the HTTP Host header.