CVE-2012-1471

EUVD-2012-1489
Directory traversal vulnerability in catalogue_file.php in ocPortal before 7.1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
ocportalocportal
𝑥
≤ 7.1.5
ocportalocportal
4.0
ocportalocportal
4.0.1
ocportalocportal
4.0.2
ocportalocportal
4.0.3
ocportalocportal
4.0.4
ocportalocportal
4.0.5
ocportalocportal
4.1
ocportalocportal
4.1.1
ocportalocportal
4.1.2
ocportalocportal
4.1.3
ocportalocportal
4.1.4
ocportalocportal
4.1.5
ocportalocportal
4.1.6
ocportalocportal
4.1.8
ocportalocportal
4.1.9
ocportalocportal
4.1.10
ocportalocportal
4.1.11
ocportalocportal
4.1.12
ocportalocportal
4.1.13
ocportalocportal
4.2
ocportalocportal
4.2:beta1
ocportalocportal
4.2:beta2
ocportalocportal
4.2:rc1
ocportalocportal
4.2:rc2
ocportalocportal
4.2:rc3
ocportalocportal
4.2.1
ocportalocportal
4.2.2
ocportalocportal
4.3
ocportalocportal
4.3:rc1
ocportalocportal
4.3:rc2
ocportalocportal
4.3:rc3
ocportalocportal
4.3.1
ocportalocportal
4.3.2
ocportalocportal
5.0
ocportalocportal
5.0:rc1
ocportalocportal
5.0.1
ocportalocportal
5.0.2
ocportalocportal
5.0.2:beta1
ocportalocportal
5.0.3
ocportalocportal
5.1:beta1
ocportalocportal
6.0
ocportalocportal
6.0:beta1
ocportalocportal
6.0:beta2
ocportalocportal
6.0:rc1
ocportalocportal
6.0:rc2
ocportalocportal
6.0:rc3
ocportalocportal
6.0.1
ocportalocportal
6.0.2
ocportalocportal
6.0.3
ocportalocportal
6.1
ocportalocportal
6.1.1
ocportalocportal
6.2:rc1
ocportalocportal
7.0
ocportalocportal
7.0.1
ocportalocportal
7.1
ocportalocportal
7.1:beta1
ocportalocportal
7.1.1
ocportalocportal
7.1.2
ocportalocportal
7.1.3
ocportalocportal
7.1.4
𝑥
= Vulnerable software versions