CVE Database
/

CVE-2012-10034

Back to search

CVE-2012-10034

Published: Aug 5, 2025

Modified: Apr 7, 2026

PUBLISHED

Description

ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outside the web root. The vulnerability is further exacerbated by null byte injection (%00) to bypass file extension checks.

VendorProductVersions

ClanSphere Project

ClanSphere

affected
2011.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now