CVE-2014-1836: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
(updated )
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.
References
- community.impresscms.org/modules/smartsection/item.php?itemid=675
- seclists.org/fulldisclosure/2014/Feb/14
- github.com/ImpressCMS/impresscms/issues/914
- github.com/advisories/GHSA-wcj4-ff9m-5r7g
- github.com/pedrib/PoC/blob/master/generic/impresscms-1.3.5.txt
- nvd.nist.gov/vuln/detail/CVE-2014-1836
- web.archive.org/web/20200228234251/http://www.securityfocus.com/bid/65279
Detect and mitigate CVE-2014-1836 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →