6.5
CVSSv2

CVE-2012-6038

Published: 26/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

admin/core/admin_func.php in razorCMS prior to 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in a fileman or (2) filemanview action. NOTE: this issue has been referred to as a "path traversal."

Vulnerable Product Search on Vulmon Subscribe to Product

razorcms razorcms 1.0

razorcms razorcms 0.3

razorcms razorcms 0.2

razorcms razorcms

razorcms razorcms 1.1

razorcms razorcms 0.4

Exploits

# Exploit Title: razorCMS 12 Path Traversal # Google Dork: "Powered by razorCMS" # Date: January 10, 2012 # Author: chap0 # Software Link: wwwrazorcmscouk/archive/core/ # Version: 12 # Tested on: Ubuntu # Patch: Upgrade to latest release 121 # Greetz To: <Insert Name Here> RazorCMS is vulnerable to Path Traversal, when logged i ...