Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thepeak_file_upload_manager | Thepeak | 1.3 (including) | 1.3 (including) |