Directory Traversal Vulnerabilities in iBrowser Plugin Library by PKP
CVE-2012-1467

Currently unrated

Key Information:

Vendor

Pkp

Vendor
CVE Published:
6 September 2012

What is CVE-2012-1467?

Multiple directory traversal vulnerabilities exist in the iBrowser plugin library utilized in Open Journal Systems before version 2.3.7. These vulnerabilities permit remote authenticated users to manipulate file actions through the exploitation of the '..' (dot dot) sequence in the 'param' parameter of the 'rfiles.php' script. Specifically, attackers may gain the potential to delete or rename arbitrary files on the server, posing significant risks to data integrity and security.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.