Total vulnerabilities in the database
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
CVSS v2:
No CWE or OWASP classifications available.