Sploitus

CVE-2013-1468

9 known exploits for CVE-2013-1468

Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.

Affected products
Piwigo
Piwigo
≤ 2.4.6, 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.2.0, 1.2.1, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.4.0, 1.4.1, 1.5.0, 1.5.1, 1.5.2, 1.6.0, 1.6.1, 1.6.2, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 2.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.1.0, 2.1.1, 2.1.2, 2.1.3
Fix
Available
CVSS 2.0
7.6 HIGH
EPSS
5.7% (93th percentile)
Weakness
CWE-352
NVD status
Modified
Published
2013-03-12
CVE-2013-1468 at NVD
Authoritative description, scoring and affected products

9 known exploits for CVE-2013-1468

Proof-of-concept code and exploit modules indexed by Sploitus