download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fd_script | Vlad_leont | 1.3 (including) | 1.3 (including) |
Fd_script | Vlad_leont | 1.3.1 (including) | 1.3.1 (including) |
Fd_script | Vlad_leont | 1.3.2 (including) | 1.3.2 (including) |