PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
CVE:
CVE-2009-1479 (Directory traversal vulnerability in client/desktop/default.htm in Boxalino before 09.05.25-0421 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.)