← Back

CVE-2013-5692

nvd nist
Published: Sep 30, 2013Modified: Apr 29, 2026

JSON object

Loading...
8.5
Vector
AV:N/AC:M/Au:S/C:C/I:C/A:C
Exploitability: 6.8 / Impact: 10.0
Source: NVD

Description

Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.

Affected (31)

Products: X2engine: X2crm
1 product
X2crm
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
X2engine
Up to 3.4.1
Version 1.0.1
Version 1.0
Version 1.1.0
Version 1.2.0
Version 1.2.1
Version 1.2.2
Version 1.3.1
Version 1.3
Version 2.2.1
Version 2.2
Version 2.5.2
Version 2.5
Version 2.7.1
Version 2.7.2
Version 2.7
Version 2.8.1
Version 2.8
Version 2.9.1
Version 2.9
Version 3.0.1
Version 3.0.2
Version 3.0
Version 3.1.1
Version 3.1.2
Version 3.1
Version 3.2
Version 3.3.1
Version 3.3.2
Version 3.3
Version 3.4

References (8)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.