CVE-2008-0489
Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
Date published : 2008-01-30
http://www.securityfocus.com/bid/27471
http://www.securityfocus.com/archive/1/487132/100/0/threaded