A vulnerability has been identified in SiteDepth CMS, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "ShowImage.php" script that does not properly validate the "name" parameter before being passed as an argument to a "readfile()" call, which could be exploited by attackers to download certain files from a vulnerable server.
Vulnerable Products
Vulnerable Software: SiteDepth CMS version 3.44 and prior