[原文]Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.
AppServ contains a flaw that may allow a remote attacker to retrieve arbitrary files. The issue is due to the 'appserv/main.php' script not properly sanitizing user input supplied to the 'appserv_root' variable. This may allow an attacker to include a file from a remote host and execute arbitrary commands leading to a loss of integrity.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.