CVE-2012-4031 Information

Share on:

Description

Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) langid cookie to port 85.

Reference

http://osvdb.org/83636 http://secunia.com/advisories/49776 http://www.exploit-db.com/exploits/19526 http://www.securityfocus.com/bid/54267 https://exchange.xforce.ibmcloud.com/vulnerabilities/76682