ID:4230 - Exploit for Path traversal in Piwigo - CVE-2013-1469

 
Main Vulnerability Database Exploits ID:4230 - Exploit for Path traversal in Piwigo - CVE-2013-1469

ID:4230 - Exploit for Path traversal in Piwigo - CVE-2013-1469

Published: August 11, 2020


Vulnerability identifier: #VU43006
Vulnerability risk: Medium
CVE-ID: CVE-2013-1469
CWE-ID: CWE-22
Exploitation vector: Remote access
Vulnerable software:
Piwigo

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in install.php in Piwigo before 2.4.7. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to read and delete arbitrary files via a . (dot dot) in the dl parameter.


Remediation

Install update from vendor's website.