Magento Server MAGMI (aka Magento Mass Importer) contains a directory traversal vulnerability in web/ajax_pluginconf.php. that allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
id: CVE-2015-2067
info:
name: Magento Server MAGMI - Directory Traversal
author: daffainfo
se
...