MEDIUM
Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .
Published Mar 13, 2013
4.0
MEDIUMCVSS 2.0
EPSS 56.01%
Description
Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.
Affected products
No data.
OR
- ≤ 2.4.6
- 1.0.0
- 1.0.1
- 1.0.2
- 1.1.0
- 1.2.0
- 1.2.1
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.4.0
- 1.4.1
- 1.5.0
- 1.5.1
- 1.5.2
- 1.6.0
- 1.6.1
- 1.6.2
- 1.7.0
- 1.7.1
- 1.7.2
- 1.7.3
- 2.0
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.0.10
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.5
- 2.3.0
- 2.3.1
- 2.3.2
- 2.3.3
- 2.3.4
- 2.3.5
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://archives.neohapsis.com/archives/bugtraq/2013-02/0153.html mailing-listx_refsource_BUGTRAQExploit
- http://packetstormsecurity.com/files/120592/Piwigo-2.4.6-Cross-Site-Request-Forgery-Traversal.html x_refsource_MISCExploit
- http://piwigo.org/bugs/view.php?id=0002843 x_refsource_CONFIRM
- http://piwigo.org/forum/viewtopic.php?id=21470 x_refsource_CONFIRM
- http://piwigo.org/releases/2.4.7 x_refsource_CONFIRM
- http://www.exploit-db.com/exploits/24561 exploitx_refsource_EXPLOIT-DB
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5127.php x_refsource_MISCExploit
- https://www.htbridge.com/advisory/HTB23144 x_refsource_MISCExploit
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2013-02/0153.html | mailing-listx_refsource_BUGTRAQExploit | |
| http://packetstormsecurity.com/files/120592/Piwigo-2.4.6-Cross-Site-Request-Forgery-Traversal.html | x_refsource_MISCExploit | |
| http://piwigo.org/bugs/view.php?id=0002843 | x_refsource_CONFIRM | |
| http://piwigo.org/forum/viewtopic.php?id=21470 | x_refsource_CONFIRM | |
| http://piwigo.org/releases/2.4.7 | x_refsource_CONFIRM | |
| http://www.exploit-db.com/exploits/24561 | exploitx_refsource_EXPLOIT-DB | |
| http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5127.php | x_refsource_MISCExploit | |
| https://www.htbridge.com/advisory/HTB23144 | x_refsource_MISCExploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 13, 2013
Updated Sep 17, 2024
Reserved Jan 29, 2013
Link CVE-2013-1469
CISA Vulnrichment
Updated n/a