CVE-2014-1836: Path Traversal
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the imagepath parameter in a cancel action.
Other sources
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the imagepath parameter in a cancel action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1836?
CVE-2014-1836 is considered a high severity vulnerability due to its potential to allow arbitrary file deletion.
How do I fix CVE-2014-1836?
To fix CVE-2014-1836, upgrade to ImpressCMS version 1.3.6 or later.
What type of vulnerability is CVE-2014-1836?
CVE-2014-1836 is classified as an absolute path traversal vulnerability.
Which versions of ImpressCMS are affected by CVE-2014-1836?
ImpressCMS versions prior to 1.3.6, including 1.3.5 and earlier, are affected by CVE-2014-1836.
Who can exploit CVE-2014-1836?
CVE-2014-1836 can be exploited by remote attackers who can manipulate the image_path parameter in a cancel action.