Joomla! Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.
View the template here CVE-2009-4202.yaml
References:
http://www.exploit-db.com/exploits/8870