CVE-2012-2208
Publication date 14 August 2012
Last updated 24 July 2024
Ubuntu priority
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
Status
Package | Ubuntu Release | Status |
---|---|---|
piwigo | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
References
Other references
- https://www.htbridge.com/advisory/HTB23085
- http://www.exploit-db.com/exploits/18782
- http://secunia.com/advisories/48903
- http://piwigo.org/releases/2.3.4
- http://piwigo.org/forum/viewtopic.php?id=19173
- http://piwigo.org/bugs/view.php?id=2607
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0196.html
- https://www.cve.org/CVERecord?id=CVE-2012-2208