Description
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Remediation
References
Related Vulnerabilities
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-5270)
Oracle Database Server CVE-2008-2590 Vulnerability (CVE-2008-2590)
Joomla! Core 1.6.0 Multiple Vulnerabilities (1.6.0)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8005)