CVE-2012-2293

Directory traversal vulnerability in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allows remote authenticated users to upload files, and consequently execute arbitrary code, via a relative path.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emc:rsa_archer_smartsuite:4.3:*:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_archer_smartsuite:4.5:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:emc:rsa_archer_egrc:5.0:*:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_archer_egrc:5.1:*:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_archer_egrc:5.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:38

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2013-02/0001.html - () http://archives.neohapsis.com/archives/bugtraq/2013-02/0001.html -

Information

Published : 2013-02-06 12:05

Updated : 2024-11-21 01:38


NVD link : CVE-2012-2293

Mitre link : CVE-2012-2293

CVE.ORG link : CVE-2012-2293


JSON object : View

Products Affected

emc

  • rsa_archer_egrc
  • rsa_archer_smartsuite
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')