Directory traversal vulnerability in SpipRSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequences in the GLOBALS[typeurls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spipaccesdoc.php3.