Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) .. sequences or (2) absolute pathnames in the filename parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php_upload_tool | Php_upload_tool | 1.0 (including) | 1.0 (including) |