Help Center Live · Help Center Live · CVE-2010-1652
**Name of the Vulnerable Software and Affected Versions**
Help Center Live versions 2.0.6 through 2.1.7
**Description**
The issue allows remote attackers to read arbitrary files and possibly have other impacts via a .. (dot dot) in the `file` parameter to "module.php".
**Recommendations**
For versions 2.0.6 and 2.1.7, consider restricting access to the module.php file until a fix is available.
As a temporary workaround, avoid using the `file` parameter in the module.php file to minimize the risk of exploitation.