CVE-2024-39171

CRITICAL

Phpvibe < 11.0.46 - Path Traversal

Title source: rule
STIX 2.1

Description

Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.

Scores

CVSS v3 9.8
EPSS 0.0096
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-35
Status published
Products (1)
phpvibe/phpvibe 11.0.3 - 11.0.46
Published Jul 09, 2024
Tracked Since Feb 18, 2026