Directory Traversal Vulnerabilities in iBrowser Plugin Library by PKP
CVE-2012-1467
Currently unrated
What is CVE-2012-1467?
Multiple directory traversal vulnerabilities exist in the iBrowser plugin library utilized in Open Journal Systems before version 2.3.7. These vulnerabilities permit remote authenticated users to manipulate file actions through the exploitation of the '..' (dot dot) sequence in the 'param' parameter of the 'rfiles.php' script. Specifically, attackers may gain the potential to delete or rename arbitrary files on the server, posing significant risks to data integrity and security.
