CVE-2012-1112: Open-Realty
Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.
Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the select_users_template parameter to index.php.
Affected products
- Open-Realty Open-Realty: up to and including 2.5.8; version 2.3.1 only; version 2.3.4 only
Published 2012-09-06. Last modified 2026-06-16.