CVE-2012-2435 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha parameter to module.php as demonstrated by cross-site request forgery (CSRF) attacks.
Reference
http://forums.pligg.com/downloads.php?do=file&id=15 http://pligg.svn.sourceforge.net/viewvc/pligg?view=revision&revision=2440 https://www.htbridge.com/advisory/HTB23089
Share on: