CVE-2011-2780

NUCLEI

Chyrp < 2.0 - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2011-2744.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Wireghoul · textwebappsphp
https://www.exploit-db.com/exploits/35946

Nuclei Templates (1)

Chyrp 2.x - Local File Inclusion
MEDIUMby daffainfo

Scores

EPSS 0.0389
EPSS Percentile 88.3%

Details

CWE
CWE-22
Status published
Products (1)
chyrp/chyrp < 2.0
Published Jul 19, 2011
Tracked Since Feb 18, 2026