Joomla! Image Browser 0.1.5 rc2 is susceptible to local file inclusion via com_imagebrowser which could allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder parameter to index.php.
View the template here CVE-2008-4668.yaml
References:
https://www.exploit-db.com/exploits/6618