CVE-2012-5918

razorCMS 1.2 - Authenticated Directory Traversal via Directory Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5918. PoCs published by chap0.

AI-analyzed exploit summary The exploit details a path traversal vulnerability in razorCMS 1.2, allowing least privileged users to access restricted directories and files by manipulating the 'dir' parameter in URLs. It includes examples of vulnerable endpoints and a timeline of vendor communication.

Description

razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a directory.

Exploits (1)

exploitdb WRITEUP VERIFIED
by chap0 · textwebappsphp
https://www.exploit-db.com/exploits/18344

The exploit details a path traversal vulnerability in razorCMS 1.2, allowing least privileged users to access restricted directories and files by manipulating the 'dir' parameter in URLs. It includes examples of vulnerable endpoints and a timeline of vendor communication.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: razorCMS 1.2
Auth required
Prerequisites: Valid user credentials · Access to the admin interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18344

Scores

EPSS 0.0152
EPSS Percentile 71.3%

Details

CWE
CWE-264
Status published
Products (1)
razorcms/razorcms 1.2
Published Nov 19, 2012
Tracked Since Feb 18, 2026