CVE-2012-1089
published 2012-03-23CVE-2012-1089: Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
5.52%
91.9th percentile
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cp23-9h5q-3326: Directory traversal vulnerability in Apache Wicket 1
ghsa_unreviewed·2022-05-17
CVE-2012-1089 [MEDIUM] CWE-22 GHSA-cp23-9h5q-3326: Directory traversal vulnerability in Apache Wicket 1
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
Red Hat
nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
vendor_redhat·2011-04-19·CVSS 3.3
CVE-2011-1749 [LOW] nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Statement: This issue did not affect the versions of nfs-utils as shipped with Red Hat Enterprise Linux 4 as it did not include include mount.nfs. It was addressed in Red Hat Enterprise Linux 5 and 6 via RHSA-2012:0310 and RHSA-2011:1534 respectively.
Package: nfs-utils (Red Hat Enterprise Linux 4) - Not affected
No detection rules found.
No public exploits indexed.
http://osvdb.org/80301http://wicket.apache.org/2012/03/22/wicket-cve-2012-1089.htmlhttp://www.securityfocus.com/bid/52679https://exchange.xforce.ibmcloud.com/vulnerabilities/74276http://osvdb.org/80301http://wicket.apache.org/2012/03/22/wicket-cve-2012-1089.htmlhttp://www.securityfocus.com/bid/52679https://exchange.xforce.ibmcloud.com/vulnerabilities/74276
2012-03-23
Published