cbcvebase.
CVE-2010-3692
published 2010-10-07

CVE-2010-3692: Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create…

PriorityP338medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
3.63%
88.2th percentile
Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directory traversal sequences in a Proxy Granting Ticket IOU (PGTiou) parameter.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
apereophpcas<= 1.1.2
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
apereophpcas
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.