CVE-2013-5692

EUVD-2013-5529
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
x2enginex2crm
𝑥
≤ 3.4.1
x2enginex2crm
1.0
x2enginex2crm
1.0.1
x2enginex2crm
1.1.0
x2enginex2crm
1.2.0
x2enginex2crm
1.2.1
x2enginex2crm
1.2.2
x2enginex2crm
1.3
x2enginex2crm
1.3.1
x2enginex2crm
2.2
x2enginex2crm
2.2.1
x2enginex2crm
2.5
x2enginex2crm
2.5.2
x2enginex2crm
2.7
x2enginex2crm
2.7.1
x2enginex2crm
2.7.2
x2enginex2crm
2.8
x2enginex2crm
2.8.1
x2enginex2crm
2.9
x2enginex2crm
2.9.1
x2enginex2crm
3.0
x2enginex2crm
3.0.1
x2enginex2crm
3.0.2
x2enginex2crm
3.1
x2enginex2crm
3.1.1
x2enginex2crm
3.1.2
x2enginex2crm
3.2
x2enginex2crm
3.3
x2enginex2crm
3.3.1
x2enginex2crm
3.3.2
x2enginex2crm
3.4
𝑥
= Vulnerable software versions