CVE-2013-1469

Piwigo < 2.4.6 - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/24561
exploitdb WORKING POC VERIFIED
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/24520

References (8)

Core 8
Core References
Various Sources x_refsource_confirm
http://piwigo.org/forum/viewtopic.php?id=21470
Release Notes x_refsource_confirm
http://piwigo.org/releases/2.4.7
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/24561
Various Sources x_refsource_confirm
http://piwigo.org/bugs/view.php?id=0002843
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-02/0153.html

Scores

EPSS 0.5163
EPSS Percentile 97.9%

Details

CWE
CWE-22
Status published
Products (50)
piwigo/piwigo 1.0.0
piwigo/piwigo 1.0.1
piwigo/piwigo 1.0.2
piwigo/piwigo 1.1.0
piwigo/piwigo 1.2.0
piwigo/piwigo 1.2.1
piwigo/piwigo 1.3.0
piwigo/piwigo 1.3.1
piwigo/piwigo 1.3.2
piwigo/piwigo 1.3.3
... and 40 more
Published Mar 13, 2013
Tracked Since Feb 18, 2026