CVE-2006-6185
Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to index.php.
Date published : 2006-11-30
http://www.securityfocus.com/bid/21213
http://www.securityfocus.com/archive/1/452170/100/100/threaded