PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote malicious users to execute arbitrary PHP code via a URL in the lang parameter.
otterware letterit2