Edior · Ediorcms · CVE-2008-1352
**Name of the Vulnerable Software and Affected Versions**
EdiorCMS (ecms) version 3.0
**Description**
A directory traversal issue exists in the search.php file, allowing remote attackers to read arbitrary files. This is achieved by including a .. (dot dot) in the ` SearchTemplate` parameter during a Title search.
**Recommendations**
For EdiorCMS (ecms) version 3.0, consider restricting access to the search.php file or limiting the ` SearchTemplate` parameter to prevent directory traversal attacks until a patch is available.