Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote malicious users to read arbitrary files via a ..%2F (dot dot slash) in the list parameter.
xecms xecms 1.0