Invicti detected code execution via local file inclusion, which occurs when a file from the target system is injected into the attacked page and interpreted as code.
At the beginning of the attacking phase, Invicti made an HTTP request which contained custom payload and saw the output of execution of it at this page. This means this code has been executed, and this vulnerability generally happens with inclusion of log files by LFI-vulnerable PHP scripts.
An attacker can execute malicious code by abusing the Local File Inclusion vulnerability on the server.

You can search and find all vulnerabilities
