First published: Mon Feb 03 2020(Updated: )
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TinyWebGallery Wordpress Flash Uploader | <=1.8.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2631 is a full path disclosure vulnerability in TinyWebGallery (TWG) 1.8.9 and earlier versions.
Remote attackers can exploit CVE-2013-2631 by using the parameters "twg_browserx" and "twg_browsery" in the page image.php to obtain sensitive information.
The severity of CVE-2013-2631 is medium with a CVSS score of 5.3.
To fix the full path disclosure vulnerability in TinyWebGallery, update to a version newer than 1.8.9.
You can find more information about CVE-2013-2631 at the following links: [https://packetstormsecurity.com/files/121128/TinyWebGallery-1.8.9-Path-Disclosure.html](https://packetstormsecurity.com/files/121128/TinyWebGallery-1.8.9-Path-Disclosure.html) and [https://www.isecauditors.com/advisories-2013#2013-012](https://www.isecauditors.com/advisories-2013#2013-012).