Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier allows remote attackers to include and possibly execute arbitrary local files via directory traversal sequences in the typefilter parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/28395
http://www.vupen.com/english/advisories/2006/3283