2009-06-04 18:30:00 2018-10-10 21:39:01

Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.

Vector

NETWORK

Complexity

MEDIUM

Authentication

NONE

Confidentiality

PARTIAL

Integrity

PARTIAL

Availability

PARTIAL
Tinywebgallery Tinywebgallery 1.7.6 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.5.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.4.5 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.5 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.4.4 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.4.3 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.4.2 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.4.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.4 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.3.3 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.3.2 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.3.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.2-18.04.2008 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.3-12.05.2008 (not an official CPE) Tinywebgallery Tinywebgallery 1.7.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.7 (not an official CPE) Tinywebgallery Tinywebgallery 1.6.3.4 (not an official CPE) Tinywebgallery Tinywebgallery 1.6.2 (not an official CPE) Tinywebgallery Tinywebgallery 1.6.3 (not an official CPE) Tinywebgallery Tinywebgallery 1.6 (not an official CPE) Tinywebgallery Tinywebgallery 1.6.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.5 30.10.2006 2200 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.4 13.10.2006 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.3 08.10.2006 1000 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.3.2 12.10.2006 1000 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.3.1 11.10.2006 1000 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.2 17.09.2006 1000 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.2.2 21.09.2006 1000 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.2.1 20.09.2006 1000 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.0.1 15.08.2006 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.0.2 17.08.2006 (not an official CPE) Tinywebgallery Tinywebgallery 1.5.1 03.09.2006 (not an official CPE) Tinywebgallery Tinywebgallery 1.5 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.2 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.1.2 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.1.3 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.1.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.0.4 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.0.2 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.0.3 (not an official CPE) Tinywebgallery Tinywebgallery 1.4.0.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.4 (not an official CPE) Tinywebgallery Tinywebgallery 1.3b (not an official CPE) Tinywebgallery Tinywebgallery 1.3c (not an official CPE) Tinywebgallery Tinywebgallery 1.3a (not an official CPE) Tinywebgallery Tinywebgallery 1.2 (not an official CPE) Tinywebgallery Tinywebgallery 1.3 (not an official CPE) Tinywebgallery Tinywebgallery 1.1.2 (not an official CPE) Tinywebgallery Tinywebgallery 1.1.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.1 (not an official CPE) Tinywebgallery Tinywebgallery 1.0 (not an official CPE) Claudio klingler Quixplorer 2.3.1 (not an official CPE) Claudio klingler Quixplorer 2.3.2 (not an official CPE) Claudio klingler Quixplorer 2.3 (not an official CPE) Claudio klingler Quixplorer 2.2 (not an official CPE) Claudio klingler Quixplorer 2.0 (not an official CPE) Claudio klingler Quixplorer 2.1.1 (not an official CPE) Claudio klingler Quixplorer 1.6 (not an official CPE) Claudio klingler Quixplorer 1.5 (not an official CPE) Claudio klingler Quixplorer 1.4 (not an official CPE) Claudio klingler Quixplorer 1.2 (not an official CPE) Claudio klingler Quixplorer 1.1 (not an official CPE) Claudio klingler Quixplorer 1.0 (not an official CPE)