cve/2013/CVE-2013-1468.md

21 lines
951 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2013-1468](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1468)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.
### POC
#### Reference
- http://packetstormsecurity.com/files/120592/Piwigo-2.4.6-Cross-Site-Request-Forgery-Traversal.html
2024-06-09 00:33:16 +00:00
- http://packetstormsecurity.com/files/120592/Piwigo-2.4.6-Cross-Site-Request-Forgery-Traversal.html
2024-05-26 14:27:05 +02:00
- http://www.exploit-db.com/exploits/24561
2024-06-09 00:33:16 +00:00
- http://www.exploit-db.com/exploits/24561
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.