Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded backslash sequences in the d parameter, as demonstrated by a "%5c../../%5c" sequence.Referenceshttp://www.securityfocus.com/bid/26348http://securityreason.com/securityalert/3330http://www.securityfocus.com/archive/1/482788/100/0/threadedhttp://osvdb.org/43628