baesystemsdetica.com.au
http://www.baesystemsdetica.com.au/Research/Advisories/Xibo-Directory-Traversal-Vulnerability-%28DS-2013-00 CVE-2013-5979
Nuclei
Xibo 1.2.2/1.4.1 - 'index.php?p' Directory Traversal
Record summary
CVE-2013-5979 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.
Description source: CVE List
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBXibo 1.2.2/1.4.1 - 'index.php?p' Directory TraversalExploitDB exploitby MahendraNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMXibo 1.2.2/1.4.1 - Directory TraversalCVSS 5
A directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.
Impact
An attacker can read arbitrary files on the server.
Remediation
Upgrade to a patched version of Xibo.
WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2013cvelfiedbspringsignagevuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CPE: cpe:2.3:a:springsignage:xibo:1.2.0:*:*:*:*:*:*:*
https://www.exploit-db.com/exploits/26955 https://nvd.nist.gov/vuln/detail/CVE-2013-5979 https://bugs.launchpad.net/xibo/+bug/1093967 http://www.baesystemsdetica.com.au/Research/Advisories/Xibo-Directory-Traversal-Vulnerability-(DS-2013-00 http://www.baesystemsdetica.com.au/Research/Advisories/Xibo-Directory-Traversal-Vulnerability-%28DS-2013-00
Source: ProjectDiscovery
References
4baesystemsdetica.com.au
http://www.baesystemsdetica.com.au/Research/Advisories/Xibo-Directory-Traversal-Vulnerability-(DS-2013-00 bugs.launchpad.netConfirmation
https://bugs.launchpad.net/xibo/+bug/1093967 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-5979