Vulnerability Description
Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it via a direct request to the file in submission/original/ in the associated article directory, as demonstrated using .pHp, .asp, and other extensions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pkp | Open Journal Systems | <= 2.3.6 |
References
- http://pkp.sfu.ca/ojs/RELEASE-2.3.7
- http://pkp.sfu.ca/support/forum/viewtopic.php?f=2&t=8431
- https://www.htbridge.com/advisory/HTB23079Exploit
- http://pkp.sfu.ca/ojs/RELEASE-2.3.7
- http://pkp.sfu.ca/support/forum/viewtopic.php?f=2&t=8431
- https://www.htbridge.com/advisory/HTB23079Exploit
FAQ
What is CVE-2012-1468?
CVE-2012-1468 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executab...
How severe is CVE-2012-1468?
CVE-2012-1468 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-1468?
Check the references section above for vendor advisories and patch information. Affected products include: Pkp Open Journal Systems.