« Volver al listado

CVE-2012-1468

Estado: ModificadaMedia (6)—

Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it via a direct request to the file in submission/original/ in the associated article directory, as demonstrated using .pHp, .asp, and other extensions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-1468",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-09-06T21:55:01.160",
  "references": [
    {
      "url": "http://pkp.sfu.ca/ojs/RELEASE-2.3.7",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://pkp.sfu.ca/support/forum/viewtopic.php?f=2&t=8431",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.htbridge.com/advisory/HTB23079",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://pkp.sfu.ca/ojs/RELEASE-2.3.7",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://pkp.sfu.ca/support/forum/viewtopic.php?f=2&t=8431",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.htbridge.com/advisory/HTB23079",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not \".php\", then accessing it via a direct request to the file in submission/original/ in the associated article directory, as demonstrated using .pHp, .asp, and other extensions."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de lista negra incompleta en Open Journal Systems antes de v2.3.7 permite ejecutar código de su elección a usuarios remotos autenticados con permisos de 'Autor' mediante la carga de un archivo con una extensión ejecutable que no es \".php\" y luego accediendo a ese fichero a través de una solicitud directa al archivo en submission/original/ en el directorio de artículos asociados, tal y como se ha demostrado utilizando extensiones .php, .asp  y otras.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:39:35.557",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pkp:open_journal_systems:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CF799D7-B134-475A-8BA7-C50F07736A80",
              "versionEndIncluding": "2.3.6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/184.html 'CWE-184: Incomplete Blacklist'",
  "sourceIdentifier": "cve@mitre.org"
}