Loading vulnerability details…
CVSS v3.1
N/A
EPSS
2.50%
Published
Mar 27, 2007
Modified
Jun 16, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter.
Affected Products (1)
References (8)