CVE-2012-1467

Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pkp:open_journal_systems:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:37

Type Values Removed Values Added
References () http://pkp.sfu.ca/support/forum/viewtopic.php?f=2&t=8431 - () http://pkp.sfu.ca/support/forum/viewtopic.php?f=2&t=8431 -
References () https://www.htbridge.com/advisory/HTB23079 - Exploit () https://www.htbridge.com/advisory/HTB23079 - Exploit

Information

Published : 2012-09-06 21:55

Updated : 2024-11-21 01:37


NVD link : CVE-2012-1467

Mitre link : CVE-2012-1467

CVE.ORG link : CVE-2012-1467


JSON object : View

Products Affected

pkp

  • open_journal_systems
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')