CVE-2011-4713

Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
oscssoscss
𝑥
≤ 2.10
oscssoscss
1.0
oscssoscss
1.1
oscssoscss
1.2.2:rc_c
oscssoscss
2.10:prerc_f
oscssoscss
2.10:prerc_g1
oscssoscss
2.10:prerc12
oscssoscss
2.10:prerc30
oscssoscss
2.10:rc5
𝑥
= Vulnerable software versions