Описание
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| hardy | DNE | |
| lucid | DNE | |
| natty | ignored | end of life |
| oneiric | ignored | end of life |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needed |
| quantal | ignored | end of life |
| raring | DNE |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 95%
0.19226
Средний
7.5 High
CVSS2
Связанные уязвимости
nvd
больше 13 лет назад
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
debian
больше 13 лет назад
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3. ...
github
больше 3 лет назад
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
EPSS
Процентиль: 95%
0.19226
Средний
7.5 High
CVSS2