VulnerabilityModified
CVE-2016-1212
Directory traversal vulnerability in futomi MP Form Mail CGI Professional Edition 3.2.3 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.
LOW 2.7EPSS 2.29%
Does this matter?
Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in futomi MP Form Mail CGI Professional Edition 3.2.3 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.
- CVSS 3.0
- 2.7 LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- futomi/mp form mail cgi
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN42545812/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000069Vendor Advisory
- http://www.futomi.com/library/info/2016/201605.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN42545812/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000069Vendor Advisory
- http://www.futomi.com/library/info/2016/201605.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.