PHP Advanced Transfer Manager "directory" and "filename" Directory Traversal Issue
Description
A vulnerability has been identified in PHP Advanced Transfer Manager (phpATM), which could be exploited by attackers to bypass security checks and gain knowledge of sensitive information. This issue is caused by an input validation error in the "index.php" script when processing the "directory" and "filename" parameters, which could be exploited to conduct directory traversal attacks and download arbitrary files a vulnerable web server.
Vulnerable Products
Vulnerable Software: PHP Advanced Transfer Manager (phpATM) version 1.30 and prior