Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/19322
http://www.cubecart.com/site/forums/index.php?showtopic=5741
http://secunia.com/advisories/14272