Back to Database
Status published
Medium
CVE-2011-2744
Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote...
Vulnerability Description
Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2744
Credits & Attribution
No credits recorded in the NVD database.
References
- http://securityreason.com/securityalert/8312
- http://www.justanotherhacker.com/advisories/JAHx113.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68564
- http://www.securityfocus.com/bid/48672
- http://www.ocert.org/advisories/ocert-2011-001.html
- http://osvdb.org/73890
- http://www.securityfocus.com/archive/1/518890/100/0/threaded
- http://www.openwall.com/lists/oss-security/2011/07/13/6
- http://www.openwall.com/lists/oss-security/2011/07/13/5
- http://secunia.com/advisories/45184
More from chyrp
View All →CVE-2024-58285
Chyrp 2.5.2 Stored Cross-Site Scripting Vulnerability via Post Title
Medium
5.3
CVE-2014-7264
Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users.twig in the Users...
Low
3.5
CVE-2012-1001
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and...
Medium
6.1
CVE-2011-2780
Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier...
Medium
5
CVE-2011-2745
upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier...
Medium
6.5
Affected Vendor
chyrp
View all reports →Affected Software
chyrp
Vulnerable Versions:
0, 2.0, 2.1
Timeline
Official Publish:
July 19th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.