Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4713

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2011-4713
Last Modified 09 Dec 2011 12:00:00
Published 08 Dec 2011 02:55:08
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2011-4713

Summary

Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.

Vulnerable Systems

Application

  • Oscss 1.0

  • Oscss 1.1

  • Oscss 1.2.2

  • Oscss 2.10


References

BUGTRAQ - 20111106 osCSS2 "_ID" parameter Local file inclusion

MISC - http://www.rul3z.de/advisories/SSCHADV2011-034.txt

EXPLOIT-DB - 18099

SECUNIA - 46741

FULLDISC - 20111109 osCSS2 "_ID" parameter Local file inclusion

CONFIRM - http://oscss.svn.sourceforge.net/viewvc/oscss?view=revision&revision=3872

CONFIRM - http://forums.oscss.org/2-security/oscss2-id-parameter-local-file-inclusion-t1999.html#p11194

BUGTRAQ - 20111106 osCSS2

FULLDISC - 20111109 osCSS2


Last Updated: 27 May 2016 10:57:50