Vulnerabilities
Vulnerable Software
Piwigo:  >> Piwigo  >> 2.3.1  Security Vulnerabilities
Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.
CVSS Score
4.0
EPSS Score
0.516
Published
2013-03-13
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
CVSS Score
7.5
EPSS Score
0.192
Published
2012-08-14
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter in the configuration module, (2) installstatus parameter in the languages_new module, or (3) theme parameter in the theme module.
CVSS Score
4.3
EPSS Score
0.067
Published
2012-08-14


Contact Us

Shodan ® - All rights reserved