RULE(RULE ID:322056)

Rule General Information
Release Date: 2019-06-27
Rule Name: Piwigo Photo Gallery Project install script Directory Traversal Vulnerability (CVE-2013-1469)
Severity:
CVE ID:
Rule Protection Details
Description: Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: ExploitDB:24561
http://archives.neohapsis.com/archives/bugtraq/2013-02/0153.html
http://packetstormsecurity.com/files/120592/Piwigo-2.4.6-Cross-Site-Request-Forgery-Traversal.html
http://piwigo.org/bugs/view.php?id=0002843
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://piwigo.org/releases/2.4.7