phpWebFileManager is "a standard Web File Manager written in PHP4". A directory traversal vulnerability in the product allows remote attackers to view files and directories that reside outside the bounding HTML root directory.
Credit:
The information has been provided by r00t.
Vulnerable systems:
* phpWebFileManager version 2.0.0
Immune systems:
* phpWebFileManager version 2.0.2
Example:
By requesting such a URL as: http://www.site.com/phpwebfilemgr/index.php?f=../../../ it is possible to traverse into directories that reside outside the bound HTML root directory.