Back

CVE-2003-1542

Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (1)

Vendor Product Version
ondrej_jombik phpwebfilemanager *

GitHub Security Advisory GHSA-3jqm-hvwr-82mr

Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.54%

Top 27% most likely to be exploited

Threat Score 20.5 / 100

Data Sources

NVD EPSS GitHub