5
CVSSv2

CVE-2012-4031

Published: 17/07/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote malicious users to read arbitrary files via a .. (dot dot) in the (1) lang or (2) langid cookie to port 85.

Vulnerable Product Search on Vulmon Subscribe to Product

wangkongbao cns-1000

wangkongbao cns-1100

Exploits

# Exploit Title: WANGKONGBAO CNS-1000 and 1100 Network Security Platform UTM Directory Traversal # Date: 7/2/2012 # Exploit Author: Dillon Beresford # Vendor Homepage: wwwwangkongbaocom/productshtml # Version: CNS-1000 and 1100 The issue is in the /src/aclogloginphp langid and lang parameters stored inside the cookie Using a URL encode ...