CVE-2012-6652
Last modified
CVE-2012-6652 is a vulnerability of currently unknown severity. Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.. EPSS estimates a 4.42% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Page Flip Book Project | Page Flip Book | All versions |
References
- http://ceriksen.com/2012/07/10/wordpress-a-page-flip-book-plugin-local-file-inclusion-vulnerability/Exploit, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2014/07/30/2Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2014/07/31/8Mailing List, Third Party Advisory
- http://ceriksen.com/2012/07/10/wordpress-a-page-flip-book-plugin-local-file-inclusion-vulnerability/Exploit, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2014/07/30/2Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2014/07/31/8Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6652?
How severe is CVE-2012-6652?
How do I fix CVE-2012-6652?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-6645Cross-site scripting (XSS) vulnerability in the autocomplete…
- CVE-2012-6646F-Secure Anti-Virus, Safe Anywhere, and PSB Workstation Secu…
- CVE-2012-6647The futex_wait_requeue_pi function in kernel/futex.c in the …
- CVE-2012-6648gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and e…
- CVE-2012-6649WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers …9.8
- CVE-2012-6651Multiple directory traversal vulnerabilities in the Vitamin …
- CVE-2012-6653Unspecified vulnerability in the All Video Gallery (all-vide…
- CVE-2012-6654Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and …
- CVE-2012-6655An issue exists AccountService 0.6.37 in the user_change_pas…3.3
- CVE-2012-6656iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 …
- CVE-2012-6657The sock_setsockopt function in net/core/sock.c in the Linux…
- CVE-2012-6658Multiple cross-site scripting (XSS) vulnerabilities in Spice…
Are you affected by CVE-2012-6652?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
