Back

MEDIUM

html2ps: arbitrary file disclosure in SSI directives

Published Oct 10, 2012

Description

Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI directive. NOTE: this issue only might be a vulnerability in limited scenarios, such as if html2ps is invoked by a web application, or if a user-assisted attacker provides filenames whose contents could cause a denial of service, such as certain devices.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 10, 2012
Updated Aug 7, 2024
Reserved Apr 5, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Sep 27, 2009
ENISA EUVD
Assigner redhat
Published Oct 10, 2012
Updated Aug 7, 2024
Exploited since n/a
EUVD-2009-5022