CVE-2006-6138 - Ratable Searches
Description
Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.
Reference
http://www.securityfocus.com/bid/21294 https://www.exploit-db.com/exploits/2847