Input can be injected into an unknowing script or application by reading a file that an attacker has writen malicious data to. Generally a problem on a shared host or compromised system.