CVE-2012-2208: Path Traversal
Published Aug 14, 2012
·Updated
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
Affected Software
1 affected component
Piwigo piwigo<=2.3.3
Event History
Aug 14, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2208?
CVE-2012-2208 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2012-2208?
To fix CVE-2012-2208, upgrade Piwigo to version 2.3.4 or later.
3
What systems are affected by CVE-2012-2208?
CVE-2012-2208 affects Piwigo versions prior to 2.3.4.
4
How does CVE-2012-2208 exploit work?
CVE-2012-2208 exploits a directory traversal flaw that allows attackers to inject malicious files through the language parameter.
5
What are the consequences of CVE-2012-2208?
The consequences of CVE-2012-2208 include the unauthorized inclusion and execution of arbitrary local files on the server.