18347exploit
http://www.exploit-db.com/exploits/18347 CVE-2012-6500
Pragyan CMS 3.0 - Remote File Disclosure
Record summary
CVE-2012-6500 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPragyan CMS 3.0 - Remote File DisclosureExploitDB exploitby Or4nG.M4NNot analyzed1 file
References
482585vdb entry
http://www.osvdb.org/82585 51360vdb entry
http://www.securityfocus.com/bid/51360 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-6500