Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uploads.php.
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.