Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote malicious users to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
php upload tool php upload tool 1.0 |