CVE-2011-2744

NUCLEI

Chyrp < 2.1 - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Wireghoul · textwebappsphp
https://www.exploit-db.com/exploits/35945

Nuclei Templates (1)

Chyrp 2.x - Local File Inclusion
MEDIUMby daffainfo

Scores

EPSS 0.0171
EPSS Percentile 82.4%

Details

CWE
CWE-22
Status published
Products (3)
chyrp/chyrp 2.0
chyrp/chyrp 2.1 beta1 (3 CPE variants)
chyrp/chyrp < 2.1
Published Jul 19, 2011
Tracked Since Feb 18, 2026