CVE-2012-0987
06.10.2012, 21:55
Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the icmsConfigPlugins[sanitizer_plugins][] parameter.
Vendor | Product | Version |
---|---|---|
impresscms | impresscms | 1.2:alpha1 |
impresscms | impresscms | 1.2:alpha2 |
impresscms | impresscms | 1.2:beta |
impresscms | impresscms | 1.2:final |
impresscms | impresscms | 1.2:rc1 |
impresscms | impresscms | 1.2:rc2 |
impresscms | impresscms | 1.2.1:beta |
impresscms | impresscms | 1.2.1:final |
impresscms | impresscms | 1.2.1:rc1 |
impresscms | impresscms | 1.2.3:beta |
impresscms | impresscms | 1.2.3:final |
impresscms | impresscms | 1.2.3:rc1 |
impresscms | impresscms | 1.2.3:rc2 |
impresscms | impresscms | 1.2.4:final |
impresscms | impresscms | 1.2.5:final |
impresscms | impresscms | 1.2.6:final |
impresscms | impresscms | 1.3 |
𝑥
= Vulnerable software versions
References