Description
This script is possibly vulnerable to directory traversal attacks.
Directory Traversal is a vulnerability which allows attackers to access restricted directories and read files outside of the web server's root directory.
Remediation
Your script should filter metacharacters from user input.
References
Related Vulnerabilities
WordPress Plugin Easy Forms for MailChimp Local File Inclusion (6.0.5.5)
lighttpd v1.4.34 SQL injection and path traversal
WordPress Plugin Ad Inserter-Ad Manager & AdSense Ads Directory Traversal (2.4.19)
WordPress Plugin WPS Child Theme Generator Directory Traversal (1.1)
WordPress Plugin WP Fastest Cache Directory Traversal (0.8.9.5)