Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24816
http://www.vupen.com/english/advisories/2006/0669
http://www.securityfocus.com/bid/16718
http://www.securityfocus.com/archive/1/425387