Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Flyspray | Krishan | me_1.0.1 (including) | me_1.0.1 (including) |