CVE-2013-5979
02.10.2013, 22:55
Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.
Vendor | Product | Version |
---|---|---|
springsignage | xibo | 1.2.0 |
springsignage | xibo | 1.2.0:rc1 |
springsignage | xibo | 1.2.0:rc2 |
springsignage | xibo | 1.2.1 |
springsignage | xibo | 1.2.2 |
springsignage | xibo | 1.4.0 |
springsignage | xibo | 1.4.0:rc1 |
springsignage | xibo | 1.4.1 |
𝑥
= Vulnerable software versions
References