CVE-2017-10993

Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
contaocontao_cms
𝑥
≤ 3.5.27
contaocontao_cms
4.0.0
contaocontao_cms
4.0.0:beta1
contaocontao_cms
4.0.0:rc1
contaocontao_cms
4.0.1
contaocontao_cms
4.0.2
contaocontao_cms
4.0.3
contaocontao_cms
4.0.4
contaocontao_cms
4.1.0
contaocontao_cms
4.1.0:beta1
contaocontao_cms
4.1.0:rc1
contaocontao_cms
4.1.1
contaocontao_cms
4.1.2
contaocontao_cms
4.1.3
contaocontao_cms
4.2.0
contaocontao_cms
4.2.0:beta1
contaocontao_cms
4.2.0:rc1
contaocontao_cms
4.2.1
contaocontao_cms
4.2.2
contaocontao_cms
4.2.3
contaocontao_cms
4.2.4
contaocontao_cms
4.2.5
contaocontao_cms
4.3.0
contaocontao_cms
4.3.0:rc1
contaocontao_cms
4.3.1
contaocontao_cms
4.3.2
contaocontao_cms
4.3.3
contaocontao_cms
4.3.5
contaocontao_cms
4.3.6
contaocontao_cms
4.3.7
contaocontao_cms
4.3.8
contaocontao_cms
4.3.9
contaocontao_cms
4.3.10
contaocontao_cms
4.3.11
contaocontao_cms
4.4.0
contaocontao_cms
4.4.0:beta1
contaocontao_cms
4.4.0:rc1
contaocontao_cms
4.4.0:rc2
𝑥
= Vulnerable software versions