Hi
I checked the report and it seems like the changes that need to be made to fix the issue is not big, it should be pretty easy to fix.
It looks like it will be enough to escape "dir" parameter before outputting it into the page, and that's my plan for fixing it.
I will need access to the website files (FTP or cPanel access) so I can search where that output of "dir" parameter is made. Or vulnerable php file can be provided to me so I can make changes in it.
Regards,
Volodymyr