Description
admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in a fileman or (2) filemanview action. NOTE: this issue has been referred to as a "path traversal."
Exploits (1)
References (6)
Core 6
Core References
Patch x_refsource_confirm
http://www.razorcms.co.uk/archive/core/old/razorCMS_core_v1_2_1_STABLE.zip
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/47461
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72268
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/18344
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/51344
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78230
Scores
EPSS
0.0454
EPSS Percentile
89.2%
Details
CWE
CWE-22
Status
published
Products (6)
razorcms/razorcms
0.2 (3 CPE variants)
razorcms/razorcms
0.3 (6 CPE variants)
razorcms/razorcms
0.4
razorcms/razorcms
1.0 (4 CPE variants)
razorcms/razorcms
1.1
razorcms/razorcms
< 1.2
Published
Nov 26, 2012
Tracked Since
Feb 18, 2026