I'm not familiar with PHP. Can someone explain this to a newbie?
So if your PHP file executes eval($_GET['code']), then arbitrary folks can submit whatever code they want as a parameter -- as in /index.php?code=blah -- and have your webserver run it for them.
[1] http://php.net/manual/en/function.eval.php [2] http://php.net/manual/en/reserved.variables.get.php
Although it seems like most hits are from PHP Vulnerability Hunter -- an automated whitebox fuzz testing tool capable of detected several classes of vulnerabilities in PHP web applications.