Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.Referenceshttp://archives.neohapsis.com/archives/bugtraq/2001-05/0126.htmlhttp://www.iss.net/security_center/static/9990.phphttp://www.securityfocus.com/bid/2724http://marc.info/?l=phpslash&m=99029398904419&w=2