SolarView Compact before version 6.00 is vulnerable to directory traversal via the file parameter in downloader.php. An unauthenticated attacker can read arbitrary files from the system by using path traversal sequences with a null byte bypass to access sensitive files such as /etc/passwd.
id: CVE-2023-40924
info:
name: SolarView Compact < 6.00 - Directory Traversal
author: Dhiyanesh
...