CVE-2010-2850
Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter.
Date published : 2010-07-23
http://www.securityfocus.com/bid/41404
http://www.nubuilder.com/nubuilderwww/change.php?changelog_id=14c3d1ea2a9fab