Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-1617

33
FAUCET Score

CVE-2012-1617 describes a directory traversal vulnerability in combine.php within OSClass versions prior to 2.3.6, specifically affecting the "juan_ramon osclass" product. This flaw allows remote, unauthenticated attackers to read and write arbitrary files on the server by manipulating the "type" parameter with dot-dot-slash sequences, which can be leveraged for arbitrary file uploads. The vulnerability has a CVSS score of 6.4 (Medium), indicating a network-based attack with low complexity, leading to partial confidentiality and integrity impact. While not listed on the KEV catalog, an exploit is publicly available on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.3.5CPE matchmatch criteria
cpe:2.3:a:juan_ramon:osclass:*:*:*:*:*:*:*:*
1.1CPE matchmatch criteria
cpe:2.3:a:juan_ramon:osclass:1.1:*:*:*:*:*:*:*
1.1CPE matchmatch criteria
cpe:2.3:a:juan_ramon:osclass:1.1:rc:*:*:*:*:*:*
1.2CPE matchmatch criteria
cpe:2.3:a:juan_ramon:osclass:1.2:alpha:*:*:*:*:*:*
1.2CPE matchmatch criteria
cpe:2.3:a:juan_ramon:osclass:1.2:beta:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.4MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
9.94%
Probability of exploitation in next 30 days
EPSS Percentile
95.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-36917 · Mar 7, 2012
This CVE's current EPSS score of 0.0994 is in the 94th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

archives.neohapsis.com / archives/bugtraq/2012-03/0024.html
Exploit
osclass.org / 2012/03/05/osclass-2-3-6
ExploitPatch
secunia.com / advisories/48284
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/73754
exchange.xforce.ibmcloud.com / vulnerabilities/73755
github.com / osclass/OSClass/commit/1e7626f4e1a26371480989c0b937f107ea9a6d4b
ExploitPatch
github.com / osclass/OSClass/commit/a40b76695994442644e46e1b776d79660500566a
ExploitPatch
github.com / osclass/OSClass/commit/ff7ef8a97301aaaf6a97fe46c2c27981a86b4e2f
ExploitPatch
codseq.it / advisories/osclass_directory_traversal_vulnerability
Exploit
openwall.com / lists/oss-security/2012/04/02/1
openwall.com / lists/oss-security/2012/04/02/6
openwall.com / lists/oss-security/2012/04/03/1
Exploit
openwall.com / lists/oss-security/2012/04/04/7
ExploitPatch
securityfocus.com / bid/52336
Exploit