CVE-2012-0907: Neoaxis Web Player

Medium severity, CVSS 5.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive.

Affected products

  • Neoaxis Neoaxis Web Player: up to and including 1.4; version 1.1 only; version 1.2 only; version 1.3 only

Published 2012-01-20. Last modified 2026-06-16.