This advisory details a Local File Inclusion (LFI) vulnerability in Zenphoto 1.4.10, specifically in the pluginDoc.php file. The vulnerability allows attackers to read arbitrary server files via directory traversal sequences in the 'extension' parameter.