phpPgAdmin 4.2.1 is vulnerable to local file inclusion in libraries/lib.inc.php when register globals is enabled. Remote attackers can read arbitrary files via a .. (dot dot) in the _language parameter to index.php.
View the template here CVE-2008-5587.yaml
References:
https://www.exploit-db.com/exploits/7363