5
CVSSv2

CVE-2012-1790

Published: 19/03/2012 Updated: 30/08/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote malicious users to read arbitrary files via a full pathname in the file parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

webgrind project webgrind 1.0

Exploits

webgrind 10 (file param) Local File Inclusion Vulnerability Vendor: Joakim Nygard and Jacob Oettinger Product web page: codegooglecom/p/webgrind Affected version: 10 (v102 in trunk on github) Summary: Webgrind is an Xdebug profiling web frontend in PHP5 Desc: webgrind suffers from a file inlcusion vulnerability (LFI) when input pas ...