Directory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/21906
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-2649
http://www.securityfocus.com/bid/14597
http://www.securityfocus.com/archive/1/408522
http://securitytracker.com/id?1014737
http://secunia.com/advisories/16497
http://h4cky0u.org/viewtopic.php?t=2097
http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0599.html