CVE-2012-4959
high · 10Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
10
CVSS
71.2%
EPSS (exploit prob.)
99th
EPSS percentile
2012-11-18
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| novell | file_reporter | 1.0.2 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-4959