Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter.
http://www.vuxml.org/freebsd/47bdabcf-3cf9-11da-baa2-0004614cc33d.html
http://securityreason.com/securityalert/88