PHP-Nuke security vulnerability (bb_smilies.php)

Summary
The remote host seems to be vulnerable to a security problem in PHP-Nuke (bb_smilies.php). The vulnerability is caused by inadequate processing of queries by PHP-Nuke's bb_smilies.php which results in returning the content of any file we desire (the file needs to be world-readable). A similar vulnerability in the same PHP program allows execution of arbitrary code by changing the password of the administrator of bb_smilies.
Impact
Every file that the webserver has access to can be read by anyone. It is also possible to change bb_smilies' administrator password and even execute arbitrary commands.
Solution
upgrade to the latest version (Version 4.4.1 and above). Additional information: http://www.securiteam.com/securitynews/Serious_security_hole_in_PHP-Nuke__bb_smilies_.html