{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-28T11:28:27.436","vulnerabilities":[{"cve":{"id":"CVE-2010-5281","sourceIdentifier":"cve@mitre.org","published":"2012-11-26T23:55:00.923","lastModified":"2026-06-16T23:26:28.433","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.  NOTE: some of these details are obtained from third party information."},{"lang":"es","value":"Vulnerabilidad de salto de directorio en ibrowser.php en el Plugin iBrowser TinyMCE  v1.4.1 para CMScout 2.09 , cuando magic_quotes_gpc está desactivado, permite a atacantes remotos leer archivos de su elección a través de un .. (punto punto) en el parámetro lang. NOTA: algunos de estos detalles han sido obtenidos a partir de información de terceros.\r\n"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:net4visions:ibrowser:1.4.1:*:*:*:*:*:*:*","matchCriteriaId":"CCF27BBD-CD9E-4472-BAFE-B59E139D3014"}]}]}],"references":[{"url":"http://packetstormsecurity.org/1009-exploits/cmscout209-lfi.txt","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/41634","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.johnleitch.net/Vulnerabilities/CMScout.2.09.IBrowser.TinyMCE.Plugin.Local.File.Inclusion/33","source":"cve@mitre.org"},{"url":"http://www.osvdb.org/68247","source":"cve@mitre.org","tags":["Exploit"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/62066","source":"cve@mitre.org"},{"url":"http://packetstormsecurity.org/1009-exploits/cmscout209-lfi.txt","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/41634","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.johnleitch.net/Vulnerabilities/CMScout.2.09.IBrowser.TinyMCE.Plugin.Local.File.Inclusion/33","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.osvdb.org/68247","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/62066","source":"af854a3a-2127-422b-91ae-364da2661108"}],"evaluatorImpact":"Per: http://secunia.com/advisories/41634\r\n\r\n'1) Input passed via the \"lang\" parameter to e.g. ibrowser.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources via directory traversal sequences and URL-encoded NULL bytes.\r\n\r\nSuccessful exploitation of this vulnerability requires that \"magic_quotes_gpc\" is disabled.'"}}]}