6.4
CVSSv2

CVE-2012-1617

Published: 26/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in combine.php in OSClass prior to 2.3.6 allows remote malicious users to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

juan ramon osclass 2.1.1

juan ramon osclass 2.1

juan ramon osclass 2.2.1

juan ramon osclass 1.2

juan ramon osclass

juan ramon osclass 2.2

juan ramon osclass 2.3.3

juan ramon osclass 2.0

juan ramon osclass 2.2.3

juan ramon osclass 2.2.2

juan ramon osclass 2.3.2

juan ramon osclass 2.3.4

juan ramon osclass 2.0.2

juan ramon osclass 2.0.3

juan ramon osclass 2.3.1

juan ramon osclass 2.3

juan ramon osclass 1.1

juan ramon osclass 2.0.1

Exploits

source: wwwsecurityfocuscom/bid/52336/info OSClass is prone to a directory-traversal vulnerability and an arbitrary-file-upload vulnerability An attacker can exploit these issues to obtain sensitive information and to upload arbitrary code and run it in the context of the webserver process OSClass 235 is vulnerable; prior versions m ...