In index.php on line 12:
<?php if (isset($_GET['body']) and !empty($_GET['body'])) include($_GET['body']); else include("home.php"); ?>
body is used without any input validation. This can lead to a local file inclusion vulnerability. For more information about LFI and remediation look here.