Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.Referenceshttp://osvdb.org/36016https://exchange.xforce.ibmcloud.com/vulnerabilities/34240http://0day.2600.ir/exploits/3901http://www.vupen.com/english/advisories/2007/1782https://www.exploit-db.com/exploits/3901http://secunia.com/advisories/25262http://www.securityfocus.com/bid/23943