V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2012-5972
CVE
MediumConfirmedExploit available

Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files v…

CVSS
5.0
Medium
EPSS
0.08
p91
Published
2012-01-01
Updated
2012-01-01
Description

Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.

Tags · CWE
CWE-23
CAPEC-76
CAPEC-139
Affected products
Specview ≤ 2.5
CVSS vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.076 · p91
Known exploited (KEV)
No
Known exploits — Сканер-ВС
19455
exploitdb · https://www.exploit-db.com/exploits/19455
Enterprise
Affected software
ProductVendorStatus
specview*Tracked
Source databases
CVE