Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2013-01-12T02:00:00Z

Updated: 2024-09-16T19:00:55.620Z

Reserved: 2013-01-11T00:00:00Z

Link: CVE-2012-6500

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2013-01-12T04:33:49.243

Modified: 2013-01-23T05:00:00.000

Link: CVE-2012-6500

cve-icon Redhat

No data.