phpPaleo version 4.8b156 suffers from a local file inclusion vulnerability. A vulnerability exists in index.php for language handling that allows for local file inclusion using a null-byte attack on the 'lang' GET parameter.
bcf4cd9e85738290d9bc0e99b776529c82d32d5ead9783d4874d3f5e03be5c75