CVE-2012-5901

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
17/11/2012
Last modified:
11/04/2025

Description

DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read logs, images, or reports via a direct request to the file in the (1) log, (2) images, or (3) report directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dflabs:ptk:1.0.5:*:*:*:*:*:*:*