A vulnerability has been identified in Treble Designs 1024 CMS, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "includes/download.php" script that does not properly validate the "item" parameter before being passed as an argument to a "readfile()" call, which could be exploited by attackers to download certain files from a vulnerable server.
Vulnerable Products
Vulnerable Software: Treble Designs 1024 CMS version 0.7 and prior