Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.111
EPSS Ranking 93.4%