Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25141
http://www.vupen.com/english/advisories/2006/0936
http://www.securityfocus.com/archive/1/427329/100/0/threaded