sf_downloads of the file secure-files.php. The manipulation of the argument downloadfile leads to path traversal.This vulnerability is traded as CVE-2005-10002. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.