Mailing the story:
Debian alert: New phpsysinfo packages fix directory traversal
Albert Puigsech Galicia <ripe@7a69ezine.org> reported that phpsysinfo,
a web-based program to display status information about the system,
contains two vulnerabilities which could allow local files to be read,
or arbitrary PHP code to be executed, under the privileges of the web
server process (usually www-data). These vulnerabilities require
access to a writable directory on the system in order to be exploited.