CVE-2013-1468
Piwigo 2.4.6 - Multiple Vulnerabilities
Severity Score
7.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
4
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.
Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en el complemento LocalFiles Editor de Piwigo anterior a v2.4.7 que permite a atacantes remotos secuestrar la autenticación de los administradores para peticiones que crean ficheros arbitrarios PHP a través de vectores sin especificar.
Piwigo version 2.4.5 suffers from cross site request forgery and path traversal vulnerabilities.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-01-29 CVE Reserved
- 2013-02-28 CVE Published
- 2013-03-01 First Exploit
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-02/0153.html | Mailing List | |
http://piwigo.org/bugs/view.php?id=0002844 | X_refsource_confirm | |
http://piwigo.org/forum/viewtopic.php?id=21470 | X_refsource_confirm | |
http://piwigo.org/releases/2.4.7 | X_refsource_confirm | |
http://www.osvdb.org/90504 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/24561 | 2013-03-01 | |
http://packetstormsecurity.com/files/120592/Piwigo-2.4.6-Cross-Site-Request-Forgery-Traversal.html | 2024-09-16 | |
http://www.exploit-db.com/exploits/24561 | 2024-09-16 | |
https://www.htbridge.com/advisory/HTB23144 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/52228 | 2013-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | <= 2.4.6 Search vendor "Piwigo" for product "Piwigo" and version " <= 2.4.6" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.0.0 Search vendor "Piwigo" for product "Piwigo" and version "1.0.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.0.1 Search vendor "Piwigo" for product "Piwigo" and version "1.0.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.0.2 Search vendor "Piwigo" for product "Piwigo" and version "1.0.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.1.0 Search vendor "Piwigo" for product "Piwigo" and version "1.1.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.2.0 Search vendor "Piwigo" for product "Piwigo" and version "1.2.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.2.1 Search vendor "Piwigo" for product "Piwigo" and version "1.2.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.3.0 Search vendor "Piwigo" for product "Piwigo" and version "1.3.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.3.1 Search vendor "Piwigo" for product "Piwigo" and version "1.3.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.3.2 Search vendor "Piwigo" for product "Piwigo" and version "1.3.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.3.3 Search vendor "Piwigo" for product "Piwigo" and version "1.3.3" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.3.4 Search vendor "Piwigo" for product "Piwigo" and version "1.3.4" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.4.0 Search vendor "Piwigo" for product "Piwigo" and version "1.4.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.4.1 Search vendor "Piwigo" for product "Piwigo" and version "1.4.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.5.0 Search vendor "Piwigo" for product "Piwigo" and version "1.5.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.5.1 Search vendor "Piwigo" for product "Piwigo" and version "1.5.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.5.2 Search vendor "Piwigo" for product "Piwigo" and version "1.5.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.6.0 Search vendor "Piwigo" for product "Piwigo" and version "1.6.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.6.1 Search vendor "Piwigo" for product "Piwigo" and version "1.6.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.6.2 Search vendor "Piwigo" for product "Piwigo" and version "1.6.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.7.0 Search vendor "Piwigo" for product "Piwigo" and version "1.7.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.7.1 Search vendor "Piwigo" for product "Piwigo" and version "1.7.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.7.2 Search vendor "Piwigo" for product "Piwigo" and version "1.7.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 1.7.3 Search vendor "Piwigo" for product "Piwigo" and version "1.7.3" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0 Search vendor "Piwigo" for product "Piwigo" and version "2.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.0 Search vendor "Piwigo" for product "Piwigo" and version "2.0.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.1 Search vendor "Piwigo" for product "Piwigo" and version "2.0.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.2 Search vendor "Piwigo" for product "Piwigo" and version "2.0.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.3 Search vendor "Piwigo" for product "Piwigo" and version "2.0.3" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.4 Search vendor "Piwigo" for product "Piwigo" and version "2.0.4" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.5 Search vendor "Piwigo" for product "Piwigo" and version "2.0.5" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.6 Search vendor "Piwigo" for product "Piwigo" and version "2.0.6" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.7 Search vendor "Piwigo" for product "Piwigo" and version "2.0.7" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.8 Search vendor "Piwigo" for product "Piwigo" and version "2.0.8" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.9 Search vendor "Piwigo" for product "Piwigo" and version "2.0.9" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.0.10 Search vendor "Piwigo" for product "Piwigo" and version "2.0.10" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.1.0 Search vendor "Piwigo" for product "Piwigo" and version "2.1.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.1.1 Search vendor "Piwigo" for product "Piwigo" and version "2.1.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.1.2 Search vendor "Piwigo" for product "Piwigo" and version "2.1.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.1.3 Search vendor "Piwigo" for product "Piwigo" and version "2.1.3" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.1.4 Search vendor "Piwigo" for product "Piwigo" and version "2.1.4" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.1.5 Search vendor "Piwigo" for product "Piwigo" and version "2.1.5" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.1.6 Search vendor "Piwigo" for product "Piwigo" and version "2.1.6" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.2.0 Search vendor "Piwigo" for product "Piwigo" and version "2.2.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.2.1 Search vendor "Piwigo" for product "Piwigo" and version "2.2.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.2.2 Search vendor "Piwigo" for product "Piwigo" and version "2.2.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.2.3 Search vendor "Piwigo" for product "Piwigo" and version "2.2.3" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.2.4 Search vendor "Piwigo" for product "Piwigo" and version "2.2.4" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.2.5 Search vendor "Piwigo" for product "Piwigo" and version "2.2.5" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.3.0 Search vendor "Piwigo" for product "Piwigo" and version "2.3.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.3.1 Search vendor "Piwigo" for product "Piwigo" and version "2.3.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.3.2 Search vendor "Piwigo" for product "Piwigo" and version "2.3.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.3.3 Search vendor "Piwigo" for product "Piwigo" and version "2.3.3" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.3.4 Search vendor "Piwigo" for product "Piwigo" and version "2.3.4" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.3.5 Search vendor "Piwigo" for product "Piwigo" and version "2.3.5" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.4.0 Search vendor "Piwigo" for product "Piwigo" and version "2.4.0" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.4.1 Search vendor "Piwigo" for product "Piwigo" and version "2.4.1" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.4.2 Search vendor "Piwigo" for product "Piwigo" and version "2.4.2" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.4.3 Search vendor "Piwigo" for product "Piwigo" and version "2.4.3" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.4.4 Search vendor "Piwigo" for product "Piwigo" and version "2.4.4" | - |
Affected
| ||||||
Piwigo Search vendor "Piwigo" | Piwigo Search vendor "Piwigo" for product "Piwigo" | 2.4.5 Search vendor "Piwigo" for product "Piwigo" and version "2.4.5" | - |
Affected
|