CVE-2010-3692: Path Traversal
Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directory traversal sequences in a Proxy Granting Ticket IOU (PGTiou) parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3692?
CVE-2010-3692 is considered a medium severity vulnerability due to the potential for remote file manipulation.
How do I fix CVE-2010-3692?
To fix CVE-2010-3692, upgrade phpCAS to version 1.1.3 or later where the vulnerability has been addressed.
Who is affected by CVE-2010-3692?
CVE-2010-3692 affects all versions of phpCAS prior to 1.1.3, particularly when proxy mode is enabled.
What type of vulnerability is CVE-2010-3692?
CVE-2010-3692 is a directory traversal vulnerability that allows unauthorized file creation or overwriting.
Can CVE-2010-3692 be exploited remotely?
Yes, CVE-2010-3692 can be exploited remotely by attackers sending crafted requests with directory traversal sequences.