V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2013-5979
CVE
MediumConfirmedExploit available

Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrar…

CVSS
5.0
Medium
EPSS
0.18
p96
Published
2013-01-01
Updated
2013-01-01
Description

Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.

Tags · CWE
CWE-22
CAPEC-64
CAPEC-76
CAPEC-78
CAPEC-79
CAPEC-126
Affected products
Xibo
CVSS vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.183 · p96
Known exploited (KEV)
No
Known exploits — Сканер-ВС
26955
exploitdb · https://www.exploit-db.com/exploits/26955
Enterprise
Affected products
ProductVendorStatus
xibo*Tracked
Source databases
CVE