5

CVE-2012-1471

Exploit
Directory traversal vulnerability in catalogue_file.php in ocPortal before 7.1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ocportal ≫ Ocportal Version <= 7.1.5
Ocportal ≫ Ocportal Version 4.0
Ocportal ≫ Ocportal Version 4.0.1
Ocportal ≫ Ocportal Version 4.0.2
Ocportal ≫ Ocportal Version 4.0.3
Ocportal ≫ Ocportal Version 4.0.4
Ocportal ≫ Ocportal Version 4.0.5
Ocportal ≫ Ocportal Version 4.1
Ocportal ≫ Ocportal Version 4.1.1
Ocportal ≫ Ocportal Version 4.1.2
Ocportal ≫ Ocportal Version 4.1.3
Ocportal ≫ Ocportal Version 4.1.4
Ocportal ≫ Ocportal Version 4.1.5
Ocportal ≫ Ocportal Version 4.1.6
Ocportal ≫ Ocportal Version 4.1.8
Ocportal ≫ Ocportal Version 4.1.9
Ocportal ≫ Ocportal Version 4.1.10
Ocportal ≫ Ocportal Version 4.1.11
Ocportal ≫ Ocportal Version 4.1.12
Ocportal ≫ Ocportal Version 4.1.13
Ocportal ≫ Ocportal Version 4.2
Ocportal ≫ Ocportal Version 4.2 Update beta1
Ocportal ≫ Ocportal Version 4.2 Update beta2
Ocportal ≫ Ocportal Version 4.2 Update rc1
Ocportal ≫ Ocportal Version 4.2 Update rc2
Ocportal ≫ Ocportal Version 4.2 Update rc3
Ocportal ≫ Ocportal Version 4.2.1
Ocportal ≫ Ocportal Version 4.2.2
Ocportal ≫ Ocportal Version 4.3
Ocportal ≫ Ocportal Version 4.3 Update rc1
Ocportal ≫ Ocportal Version 4.3 Update rc2
Ocportal ≫ Ocportal Version 4.3 Update rc3
Ocportal ≫ Ocportal Version 4.3.1
Ocportal ≫ Ocportal Version 4.3.2
Ocportal ≫ Ocportal Version 5.0
Ocportal ≫ Ocportal Version 5.0 Update rc1
Ocportal ≫ Ocportal Version 5.0.1
Ocportal ≫ Ocportal Version 5.0.2
Ocportal ≫ Ocportal Version 5.0.2 Update beta1
Ocportal ≫ Ocportal Version 5.0.3
Ocportal ≫ Ocportal Version 5.1 Update beta1
Ocportal ≫ Ocportal Version 6.0
Ocportal ≫ Ocportal Version 6.0 Update beta1
Ocportal ≫ Ocportal Version 6.0 Update beta2
Ocportal ≫ Ocportal Version 6.0 Update rc1
Ocportal ≫ Ocportal Version 6.0 Update rc2
Ocportal ≫ Ocportal Version 6.0 Update rc3
Ocportal ≫ Ocportal Version 6.0.1
Ocportal ≫ Ocportal Version 6.0.2
Ocportal ≫ Ocportal Version 6.0.3
Ocportal ≫ Ocportal Version 6.1
Ocportal ≫ Ocportal Version 6.1.1
Ocportal ≫ Ocportal Version 6.2 Update rc1
Ocportal ≫ Ocportal Version 7.0
Ocportal ≫ Ocportal Version 7.0.1
Ocportal ≫ Ocportal Version 7.1
Ocportal ≫ Ocportal Version 7.1 Update beta1
Ocportal ≫ Ocportal Version 7.1.1
Ocportal ≫ Ocportal Version 7.1.2
Ocportal ≫ Ocportal Version 7.1.3
Ocportal ≫ Ocportal Version 7.1.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.01% 0.783
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://ocportal.com/site/news/view/new-releases/ocportal-7-1-6-released.htm
Vendor Advisory
http://ocportal.com/site/news/view/ocportal-security-update.htm
Patch
Vendor Advisory
https://www.htbridge.com/advisory/HTB23078
Exploit