6.8
CVSSv2

CVE-2011-2744

Published: 19/07/2011 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Chyrp 2.1 and previous versions allows remote malicious users to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.

Vulnerable Product Search on Vulmon Subscribe to Product

chyrp chyrp

chyrp chyrp 2.1

chyrp chyrp 2.0

Exploits

source: wwwsecurityfocuscom/bid/48672/info Chyrp is prone to multiple cross-site scripting vulnerabilities, a local file-include vulnerability, an arbitrary file-upload vulnerability, and a directory-traversal vulnerability An attacker may leverage these issues to execute arbitrary script code on an affected computer and in the brow ...