KR-Web 1.1b2 and prior contain a remote file inclusion vulnerability via adm/krgourl.php, which allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.
View the template here CVE-2009-4223.yaml
References:
https://sourceforge.net/projects/krw/