Vendor: http://hypersilence.net Version(s): Silentum Uploader 1.4.0 (May also affect earlier versions) Credit: Danny Moules Critical: Yes See PUSH 55 Advisory at http://www.push55.co.uk/advisories.php?id=2 ---- Due to insufficient validation of client-side data, we can alter the path of files to be deleted to a file outside the intended directory. The following PoC will delete a file named 'secret.txt' one level above the application folder. You must have already uploaded a file or you can visit APPLICATIONFOLDER/upload_log.txt (on a default installation) to ascertain the name of existing files. ---