Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Es.one | Thinking_arts | 1.0 (including) | 1.0 (including) |
References