Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/19896
http://www.securityfocus.com/bid/12917
http://www.gulftech.org/?node=research&article_id=00065-03292005