RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16817
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-2053
http://www.securityfocus.com/bid/10812
http://securitytracker.com/id?1010788