Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. The security focus bid link states that this is a local file include vulnerability.
Publication date: Wed, 20 Feb 2008 02:44:00 +0000