CVE-2012-1468
Last modified
CVE-2012-1468 is a vulnerability of currently unknown severity. Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it via a direct request to the file in submission/original/ in the associated article directory, as demonstrated using .pHp, .asp, and other extensions.. EPSS estimates a 3.48% chance of exploitation in the next 30 days.
Description
Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it via a direct request to the file in submission/original/ in the associated article directory, as demonstrated using .pHp, .asp, and other extensions.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pkp | Open Journal Systems | <= 2.3.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1468?
How severe is CVE-2012-1468?
How do I fix CVE-2012-1468?
Are you affected by CVE-2012-1468?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
