Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.
- http://sourceforge.net/mailarchive/message.php?msg_id=12318248
No PoCs found on GitHub currently.