Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (dot dot slash) in the list parameter.
- https://www.exploit-db.com/exploits/4758
No PoCs found on GitHub currently.