Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hqq-6fv5-q77v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

EPSS

Процентиль: 95%
0.19226
Средний

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 13 лет назад

Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

nvd
больше 13 лет назад

Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

debian
больше 13 лет назад

Directory traversal vulnerability in upgrade.php in Piwigo before 2.3. ...

EPSS

Процентиль: 95%
0.19226
Средний

Дефекты

CWE-22