← Back

CVE-2012-6064

nvd nist
Published: Dec 3, 2012Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be leveraged using CSRF (CVE-2012-5450) to allow remote attackers to delete arbitrary files.

Affected (86)

1 product
Cms Made Simple
Configuration A
86 vulnerable
Vulnerable SoftwareAffected Versions
Cmsmadesimple
Up to 1.11.2
Version 0.10.1
Version 0.10.2
Version 0.10.3
Version 0.10.4
Version 0.10
Version 0.11.1
Version 0.11.2
Version 0.11
Version 0.12.1
Version 0.12.2
Version 0.12
Version 0.13
Version 0.1
Version 0.2.1
Version 0.2
Version 0.3.1
Version 0.3.2
Version 0.3
Version 0.4.1
Version 0.4
Version 0.5.1
Version 0.5
Version 0.6.1
Version 0.6.2
Version 0.6.3
Version 0.6
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7
Version 0.8.1
Version 0.8.2
Version 0.8
Version 0.9.1
Version 0.9.2
Version 0.9
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3.1
Version 1.1.3
Version 1.1.4
Version 1.1
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2
Version 1.3
Version 1.3 beta1
Version 1.3 beta2
Version 1.4.1
Version 1.4
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5.4
Version 1.5
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.6.5
Version 1.6.6
Version 1.6.7
Version 1.6
Version 1.7.1
Version 1.7
Version 1.8.1
Version 1.8.2
Version 1.8
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.4.1
Version 1.9.4.2
Version 1.9.4
Version 1.9

Timeline

No history available yet.