Researcher: hackberry.ath.cx Ref: Request It : Song Request System 1.0b - remote file inclusion http://www.securityfocus.com/archive/1/archive/1/465081/100/0/threaded Source inspection confirmed this: if(isset($id)) { if($id == 'home') { $id = "list"; } include($id.".php"); } - Steve