← Back

CVE-2012-2435

nvd nist
Published: May 27, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha parameter to module.php, as demonstrated by cross-site request forgery (CSRF) attacks.

Affected (24)

Products: Pligg: Pligg Cms
1 product
Pligg Cms
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Pligg
All versions
Up to 1.2.1
Version 1.0.0
Version 1.0.0 rc1
Version 1.0.0 rc2
Version 1.0.0 rc3
Version 1.0.0 rc4
Version 1.0.0 rc5
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.1.0
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.2.0
Version 9.5
Version 9.9.0
Version 9.9.0 beta
Version 9.9.5
Version 9.9.5 beta
Version 9.9

References (6)

Timeline

No history available yet.