Lucene search

K
cve[email protected]CVE-2013-5692
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-5692

2022-10-0316:14:54
CWE-22
web.nvd.nist.gov
33
cve-2013-5692
nvd
x2engine
x2crm
directory traversal
vulnerability
remote authentication

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.1%

Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a … (dot dot) in the file parameter to index.php/admin/translationManager.

Affected configurations

NVD
Node
x2enginex2crmRange3.4.1
OR
x2enginex2crmMatch1.0
OR
x2enginex2crmMatch1.0.1
OR
x2enginex2crmMatch1.1.0
OR
x2enginex2crmMatch1.2.0
OR
x2enginex2crmMatch1.2.1
OR
x2enginex2crmMatch1.2.2
OR
x2enginex2crmMatch1.3
OR
x2enginex2crmMatch1.3.1
OR
x2enginex2crmMatch2.2
OR
x2enginex2crmMatch2.2.1
OR
x2enginex2crmMatch2.5
OR
x2enginex2crmMatch2.5.2
OR
x2enginex2crmMatch2.7
OR
x2enginex2crmMatch2.7.1
OR
x2enginex2crmMatch2.7.2
OR
x2enginex2crmMatch2.8
OR
x2enginex2crmMatch2.8.1
OR
x2enginex2crmMatch2.9
OR
x2enginex2crmMatch2.9.1
OR
x2enginex2crmMatch3.0
OR
x2enginex2crmMatch3.0.1
OR
x2enginex2crmMatch3.0.2
OR
x2enginex2crmMatch3.1
OR
x2enginex2crmMatch3.1.1
OR
x2enginex2crmMatch3.1.2
OR
x2enginex2crmMatch3.2
OR
x2enginex2crmMatch3.3
OR
x2enginex2crmMatch3.3.1
OR
x2enginex2crmMatch3.3.2
OR
x2enginex2crmMatch3.4

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.1%