The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.
http://security.gentoo.org/glsa/glsa-200802-04.xml
http://secunia.com/advisories/28898