Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ticketid and (2) filename parameters.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/38187https://www.exploit-db.com/exploits/4592http://www.securityfocus.com/bid/26277http://secunia.com/advisories/27470