Description
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Remediation
References
Related Vulnerabilities
WordPress Plugin Paid Business Listings Blind SQL Injection (1.0.2)
Jenkins Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-2101)
WordPress Plugin Gallery-Flagallery Photo Portfolio 'skin' Parameter Cross-Site Scripting (1.72)
WordPress Plugin iQ Block Country Cross-Site Scripting (1.2.11)