Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.
Fixes

Solution

SpecView recommends users download and install the update from their web site which mitigates the vulnerability.


Workaround

No workaround given by the vendor.

History

Mon, 07 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV2_0

{'score': 5.0, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N'}

cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N'}


Mon, 07 Jul 2025 20:00:00 +0000

Type Values Removed Values Added
Title SpecView Directory Traversal
Weaknesses CWE-23
References

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-07-07T19:55:10.421Z

Reserved: 2012-11-21T00:00:00Z

Link: CVE-2012-5972

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-01-17T16:55:02.237

Modified: 2025-07-07T20:15:26.170

Link: CVE-2012-5972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.