CVE-2014-1836
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.
- Affected products
- Impresscms
- Impresscms
- ≤ 1.3.5
- Fix
- Available
- CVSS 2.0
- 6.4 MEDIUM
- EPSS
- 3.7% (89th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2015-07-01
CVE-2014-1836 at NVD
3 known exploits for CVE-2014-1836
Proof-of-concept code and exploit modules indexed by Sploitus