CVE-2012-1467
Open Journal Systems < 2.3.6 - Authenticated Path Traversal via iBrowser Plugin rfiles.php param Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1467. PoCs published by High-Tech Bridge.
AI-analyzed exploit summary The exploit demonstrates arbitrary file deletion and renaming vulnerabilities in Open Journal Systems 2.3.6 due to insufficient input sanitization. It allows path traversal and file manipulation via crafted HTTP requests.
Description
Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php.
Exploits (1)
The exploit demonstrates arbitrary file deletion and renaming vulnerabilities in Open Journal Systems 2.3.6 due to insufficient input sanitization. It allows path traversal and file manipulation via crafted HTTP requests.