CVE-2014-3975
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir parameter.
Date published : 2014-06-05
http://www.exploit-db.com/exploits/33555
http://bot24.blogspot.com/2014/05/auracms-30-cross-site-scripting-local.html