CVE-2012-0998

LEPTON < 1.1.4 - Remote File Inclusion via Language Parameter Path Traversal

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the language parameter.

References (3)

Core 3
Core References

Scores

EPSS 0.0188
EPSS Percentile 76.9%

Details

CWE
CWE-22
Status published
Products (4)
lepton-cms/lepton 1.1.0
lepton-cms/lepton 1.1.1
lepton-cms/lepton 1.1.2
lepton-cms/lepton < 1.1.3
Published Feb 24, 2012
Tracked Since Feb 18, 2026