logahead is an "ajaxified blogging engine using PHP4 and mySQL database by James from the UK". A vulnerability in logahead allows remote attackers to upload arbitrary files to the server.
A remote attacher is able to upload, including PHP files, and to perform arbitrary commands inside the server victim by utilizing the following URL: http://www.server-victim/extras/plugins/widged/_widged.php?A=U&D=