Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-6038

Опубликовано: 26 нояб. 2012
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in a fileman or (2) filemanview action. NOTE: this issue has been referred to as a "path traversal."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:razorcms:razorcms:*:*:*:*:*:*:*:*
Версия до 1.2 (включая)
cpe:2.3:a:razorcms:razorcms:0.2:*:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.2:rc:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.2:rc2:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.3:*:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.3:beta:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.3:beta1:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.3:beta2:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.3:rc:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.3:rc2:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:0.4:*:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:1.0:*:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:1.0:beta:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:1.0:rc:*:*:*:*:*:*
cpe:2.3:a:razorcms:razorcms:1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.04543
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in a fileman or (2) filemanview action. NOTE: this issue has been referred to as a "path traversal."

EPSS

Процентиль: 89%
0.04543
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-22