Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the fname parameter in a view action.
id: CVE-2011-4640
info:
name: WebTitan < 3.60 - Local File Inclusion
author: ctflearner
sever
...