Vulnerability Details CVE-2011-4832
Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.048
EPSS Ranking 89.0%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2011-4832
-
cpe:2.3:a:caupo:cauposhop_classic:3.01
-
cpe:2.3:a:caupo:cauposhop_pro:*
-
cpe:2.3:a:caupo:cauposhop_pro:2.0
-
cpe:2.3:a:caupo:cauposhop_pro:2.1