Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc parameters.
- http://securityreason.com/securityalert/4290
- https://www.exploit-db.com/exploits/6413
No PoCs found on GitHub currently.