PHP/FI contains a flaw that allows a remote attacker to view arbitray files. The issue is due to the "mylog.html" sample script not sanitizing input passed to the "screen" variable. By supplying a fully qualified path and filename, the script will return the contents of the file.
Classification
Location:
Remote / Network Access
OSVDB:
Web Related
Solution
Upgrade to version 3.0 or higher, as it has been reported to fix this
vulnerability. An upgrade is required as there are no known workarounds.