Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the include parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/7580
http://www.securityfocus.com/bid/3554
http://www.menalto.com/projects/gallery/article.php?sid=33&mode=&order=