Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. (dot dot) in the deleteTorrent parameter.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/51088https://www.exploit-db.com/exploits/8931