Lucene search

K
nvd[email protected]NVD:CVE-2013-1468
HistoryMar 14, 2013 - 3:13 a.m.

CVE-2013-1468

2013-03-1403:13:32
CWE-352
web.nvd.nist.gov
7

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.316

Percentile

97.1%

Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.

Affected configurations

Nvd
Node
piwigopiwigoRange2.4.6
OR
piwigopiwigoMatch1.0.0-
OR
piwigopiwigoMatch1.0.1
OR
piwigopiwigoMatch1.0.2
OR
piwigopiwigoMatch1.1.0
OR
piwigopiwigoMatch1.2.0
OR
piwigopiwigoMatch1.2.1
OR
piwigopiwigoMatch1.3.0
OR
piwigopiwigoMatch1.3.1
OR
piwigopiwigoMatch1.3.2
OR
piwigopiwigoMatch1.3.3
OR
piwigopiwigoMatch1.3.4
OR
piwigopiwigoMatch1.4.0
OR
piwigopiwigoMatch1.4.1
OR
piwigopiwigoMatch1.5.0
OR
piwigopiwigoMatch1.5.1
OR
piwigopiwigoMatch1.5.2
OR
piwigopiwigoMatch1.6.0
OR
piwigopiwigoMatch1.6.1
OR
piwigopiwigoMatch1.6.2
OR
piwigopiwigoMatch1.7.0
OR
piwigopiwigoMatch1.7.1
OR
piwigopiwigoMatch1.7.2
OR
piwigopiwigoMatch1.7.3
OR
piwigopiwigoMatch2.0
OR
piwigopiwigoMatch2.0.0
OR
piwigopiwigoMatch2.0.1
OR
piwigopiwigoMatch2.0.2
OR
piwigopiwigoMatch2.0.3
OR
piwigopiwigoMatch2.0.4
OR
piwigopiwigoMatch2.0.5
OR
piwigopiwigoMatch2.0.6
OR
piwigopiwigoMatch2.0.7
OR
piwigopiwigoMatch2.0.8
OR
piwigopiwigoMatch2.0.9
OR
piwigopiwigoMatch2.0.10
OR
piwigopiwigoMatch2.1.0
OR
piwigopiwigoMatch2.1.1
OR
piwigopiwigoMatch2.1.2
OR
piwigopiwigoMatch2.1.3
OR
piwigopiwigoMatch2.1.4
OR
piwigopiwigoMatch2.1.5
OR
piwigopiwigoMatch2.1.6
OR
piwigopiwigoMatch2.2.0
OR
piwigopiwigoMatch2.2.1
OR
piwigopiwigoMatch2.2.2
OR
piwigopiwigoMatch2.2.3
OR
piwigopiwigoMatch2.2.4
OR
piwigopiwigoMatch2.2.5
OR
piwigopiwigoMatch2.3.0
OR
piwigopiwigoMatch2.3.1
OR
piwigopiwigoMatch2.3.2
OR
piwigopiwigoMatch2.3.3
OR
piwigopiwigoMatch2.3.4
OR
piwigopiwigoMatch2.3.5
OR
piwigopiwigoMatch2.4.0
OR
piwigopiwigoMatch2.4.1
OR
piwigopiwigoMatch2.4.2
OR
piwigopiwigoMatch2.4.3
OR
piwigopiwigoMatch2.4.4
OR
piwigopiwigoMatch2.4.5
VendorProductVersionCPE
piwigopiwigo*cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*
piwigopiwigo1.0.0cpe:2.3:a:piwigo:piwigo:1.0.0:-:*:*:*:*:*:*
piwigopiwigo1.0.1cpe:2.3:a:piwigo:piwigo:1.0.1:*:*:*:*:*:*:*
piwigopiwigo1.0.2cpe:2.3:a:piwigo:piwigo:1.0.2:*:*:*:*:*:*:*
piwigopiwigo1.1.0cpe:2.3:a:piwigo:piwigo:1.1.0:*:*:*:*:*:*:*
piwigopiwigo1.2.0cpe:2.3:a:piwigo:piwigo:1.2.0:*:*:*:*:*:*:*
piwigopiwigo1.2.1cpe:2.3:a:piwigo:piwigo:1.2.1:*:*:*:*:*:*:*
piwigopiwigo1.3.0cpe:2.3:a:piwigo:piwigo:1.3.0:*:*:*:*:*:*:*
piwigopiwigo1.3.1cpe:2.3:a:piwigo:piwigo:1.3.1:*:*:*:*:*:*:*
piwigopiwigo1.3.2cpe:2.3:a:piwigo:piwigo:1.3.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 611

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.316

Percentile

97.1%