A directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
View the template here CVE-2010-1858.yaml
References:
http://packetstormsecurity.org/1003-exploits/joomlasmestorage-lfi.txt