A vulnerability was identified in SPiD, which may be exploited by attackers to compromise a vulnerable web server. This flaw is due to an input validation error in "lang.php" when processing a specially crafted "lang_path" parameter, which may be exploited by remote attackers to include malicious files and execute arbitrary commands with the privileges of the web server.