5
CVSSv2

CVE-2013-5979

Published: 02/10/2013 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Spring Signage Xibo 1.2.x prior to 1.2.3 and 1.4.x prior to 1.4.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the p parameter to index.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

springsignage xibo 1.2.0

springsignage xibo 1.4.1

springsignage xibo 1.2.1

springsignage xibo 1.2.2

springsignage xibo 1.4.0

Exploits

Exploit Title: Xibo Directory Traversal Vulnerability Exploit Author: Mahendra Date: 2 April 2013 Vendor homepage: xiboorguk References: wwwbaesystemsdeticacomau/Research/Advisories/Xibo-Directory-Traversal-Vulnerability-(DS-2013-00 ############################ Affected Vendor: Spring Signage Ltd Affected Software: Xibo Affected ...