CVE-2012-1471

ocPortal < 7.1.6 - Path Traversal via Catalogue File Parameter

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in catalogue_file.php in ocPortal before 7.1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://ocportal.com/site/news/view/ocportal-security-update.htm

Scores

EPSS 0.0201
EPSS Percentile 78.5%

Details

CWE
CWE-22
Status published
Products (35)
ocportal/ocportal 4.0
ocportal/ocportal 4.0.1
ocportal/ocportal 4.0.2
ocportal/ocportal 4.0.3
ocportal/ocportal 4.0.4
ocportal/ocportal 4.0.5
ocportal/ocportal 4.1
ocportal/ocportal 4.1.1
ocportal/ocportal 4.1.2
ocportal/ocportal 4.1.3
... and 25 more
Published Oct 01, 2012
Tracked Since Feb 18, 2026