Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-1468
HistoryMar 14, 2013 - 12:00 a.m.

CVE-2013-1468

2013-03-1400:00:00
ubuntu.com
ubuntu.com
14

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

EPSS

0.316

Percentile

97.1%

Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor
plugin in Piwigo before 2.4.7 allows remote attackers to hijack the
authentication of administrators for requests that create arbitrary PHP
files via unspecified vectors.

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

EPSS

0.316

Percentile

97.1%