CVE-2013-5692

Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
x2enginex2crm
𝑥
≤ 3.4.1
x2enginex2crm
1.0
x2enginex2crm
1.0.1
x2enginex2crm
1.1.0
x2enginex2crm
1.2.0
x2enginex2crm
1.2.1
x2enginex2crm
1.2.2
x2enginex2crm
1.3
x2enginex2crm
1.3.1
x2enginex2crm
2.2
x2enginex2crm
2.2.1
x2enginex2crm
2.5
x2enginex2crm
2.5.2
x2enginex2crm
2.7
x2enginex2crm
2.7.1
x2enginex2crm
2.7.2
x2enginex2crm
2.8
x2enginex2crm
2.8.1
x2enginex2crm
2.9
x2enginex2crm
2.9.1
x2enginex2crm
3.0
x2enginex2crm
3.0.1
x2enginex2crm
3.0.2
x2enginex2crm
3.1
x2enginex2crm
3.1.1
x2enginex2crm
3.1.2
x2enginex2crm
3.2
x2enginex2crm
3.3
x2enginex2crm
3.3.1
x2enginex2crm
3.3.2
x2enginex2crm
3.4
𝑥
= Vulnerable software versions