« Volver al listado

CVE-2012-5171

Estado: ModificadaMedia (5)—

Una vulnerabilidad de salto de directorio en Be Graph BeZIP antes de v3.10 permite a atacantes remotos crear o sobreescribir archivos de su elección a través de un archivo de almacenamiento modificado.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-5171",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-11-08T11:46:24.753",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN18223913/995378/index.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN18223913/index.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2012-000101",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.be-graph.com/bgi/product/bezip/secure1.html#en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.securityfocus.com/bid/56488",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79916",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN18223913/995378/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN18223913/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2012-000101",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.be-graph.com/bgi/product/bezip/secure1.html#en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/56488",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79916",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Directory traversal vulnerability in Be Graph BeZIP before 3.10 allows remote attackers to create or overwrite arbitrary files via a crafted archive file."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de salto de directorio en Be Graph BeZIP antes de v3.10 permite a atacantes remotos crear o sobreescribir archivos de su elección a través de un archivo de almacenamiento modificado."
    }
  ],
  "lastModified": "2026-06-16T23:46:22.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:be-graph:bezip:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "608E5592-DE1A-4BB7-A010-269E69CD87C7",
              "versionEndIncluding": "3.04"
            },
            {
              "criteria": "cpe:2.3:a:be-graph:bezip:3.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C867193-ADD8-460F-BD74-78DE2076EF28"
            },
            {
              "criteria": "cpe:2.3:a:be-graph:bezip:3.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34B49672-12E1-4955-B540-4032EAB6DD7B"
            },
            {
              "criteria": "cpe:2.3:a:be-graph:bezip:3.03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5977971-45C7-4E58-A255-F6F788D105B8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}