Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25861
http://www.securityfocus.com/archive/1/431068
http://www.securityfocus.com/archive/1/431012
http://www.oscommerce.com/community/bugs%2C2835
http://sourceforge.net/mailarchive/message.php?msg_id=12318248