CVE-2012-6500: Pragyan CMS Project Pragyan CMS

Medium severity, CVSS 5.0. EPSS: 3.4% chance of exploitation in the next 30 days.

Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.

Affected products

  • Pragyan CMS Project Pragyan CMS: up to and including 3.0; version 2.5.4 only; version 2.5.9 only; version 2.5.12 only; version 2.5.13 only; version 2.5.14 only; …

Published 2013-01-12. Last modified 2026-06-16.