CVE-2013-5692

Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
x2enginex2crm
𝑥
≤ 3.4.1
x2enginex2crm
1.0
x2enginex2crm
1.0.1
x2enginex2crm
1.1.0
x2enginex2crm
1.2.0
x2enginex2crm
1.2.1
x2enginex2crm
1.2.2
x2enginex2crm
1.3
x2enginex2crm
1.3.1
x2enginex2crm
2.2
x2enginex2crm
2.2.1
x2enginex2crm
2.5
x2enginex2crm
2.5.2
x2enginex2crm
2.7
x2enginex2crm
2.7.1
x2enginex2crm
2.7.2
x2enginex2crm
2.8
x2enginex2crm
2.8.1
x2enginex2crm
2.9
x2enginex2crm
2.9.1
x2enginex2crm
3.0
x2enginex2crm
3.0.1
x2enginex2crm
3.0.2
x2enginex2crm
3.1
x2enginex2crm
3.1.1
x2enginex2crm
3.1.2
x2enginex2crm
3.2
x2enginex2crm
3.3
x2enginex2crm
3.3.1
x2enginex2crm
3.3.2
x2enginex2crm
3.4
𝑥
= Vulnerable software versions