6.5
CVSSv2

CVE-2012-1467

Published: 06/09/2012 Updated: 13/09/2012
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems prior to 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pkp open journal systems

Exploits

source: wwwsecurityfocuscom/bid/52666/info Open Journal Systems is prone to following multiple vulnerabilities because the software fails to sufficiently sanitize user-supplied input: 1 An arbitrary-file-deletion vulnerability 2 A security vulnerability 3 An arbitrary-file-upload vulnerability 4 Multiple cross-site scripting ...
Open Journal Systems version 236 suffers from file manipulation, cross site scripting, and shell upload vulnerabilities ...