vendor:
Piwigo
by:
High-Tech Bridge Security Research Lab
7,6
CVSS
HIGH
Cross-Site Request Forgery [CWE-352], Path Traversal [CWE-22]
352, 22
CWE
Product Name: Piwigo
Affected Version From: 2.4.6
Affected Version To: 2.4.6
Patch Exists: YES
Related CWE: CVE-2013-1468, CVE-2013-1469
CPE: a:piwigo_project:piwigo
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Multiple Vulnerabilities in Piwigo
The vulnerability exists due to insufficient verification of the HTTP request origin in "/admin.php" script. A remote attacker can trick a logged-in administrator to visit a specially crafted webpage and create arbitrary PHP file on the remote server. The vulnerability exists due to insufficient filtration of user-supplied input in "dl" HTTP GET parameter passed to "/install.php" script. A remote attacker can manipulate the "dl" parameter to read arbitrary files on the remote server.
Mitigation:
Update to the latest version of Piwigo.