Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/22249
http://securityreason.com/securityalert/4