5
CVSSv2

CVE-2012-6522

Published: 31/01/2013 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote malicious users to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

w-cms w-cms 2.01

Exploits

# Exploit Title: W-Cms Multiple Vulnerability # Date: 2012-01-09 # Author: th3g4m3_0v3r # Site:w-cmsinfo/ # Software Link: codegooglecom/p/wcms/ # Dork: intext:"Powered by w-CMS" # Version : [201] # Tested on: Window 7 # Yogesh Kashyap, shubneet goel, w4rl0ckd0wn, Chip, VzAcnY, Razzy, Sayan, Jaggi Panu, Darkgt # wwwh4ck3rin, w ...
+----------------------------------------------------------------------+ | ____ _ _ _____ _____ | | | _ \| | | | |_ _| __ \ | | | |_) | | __ _ ___| | __ _____ | | | | | | | | | _ <| |/ _` |/ __| |/ / |_____|| | | | | ...