PT-2012-3130 · Fork Cms · Fork Cms

Published

2012-02-20

·

Updated

2022-05-17

·

CVE-2012-1207

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fork CMS versions 3.2.4 and earlier
Description A directory traversal issue allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter to "frontend/js.php". This could potentially expose sensitive information.
Recommendations For Fork CMS versions 3.2.4 and earlier, update to version 3.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the "frontend/js.php" endpoint until a patch is available. Avoid using the module parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1207
GHSA-4X28-J85R-668Q

Affected Products

Fork Cms