Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17745
http://www.securityfocus.com/bid/11437
http://securitytracker.com/id?1011748