CVE-2012-6500

EUVD-2012-6350
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
pragyan_cms_projectpragyan_cms
𝑥
≤ 3.0
pragyan_cms_projectpragyan_cms
2.5.4
pragyan_cms_projectpragyan_cms
2.5.9
pragyan_cms_projectpragyan_cms
2.5.12
pragyan_cms_projectpragyan_cms
2.5.13
pragyan_cms_projectpragyan_cms
2.5.14
pragyan_cms_projectpragyan_cms
2.6.1
pragyan_cms_projectpragyan_cms
2.6.2
pragyan_cms_projectpragyan_cms
2.6.3
pragyan_cms_projectpragyan_cms
2.6.4
𝑥
= Vulnerable software versions