phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6048
Reference (s):
- https://www.phpmyfaq.de/security/advisory-2014-09-16
- http://techdefencelabs.com/security-advisories.html