← Back

CVE-2017-10993

nvd nist
Published: Jul 21, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.

Affected (38)

Products: Contao: Contao Cms
1 product
Contao Cms
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Contao
Up to 3.5.27
Version 4.0.0
Version 4.0.0 beta1
Version 4.0.0 rc1
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.1.0
Version 4.1.0 beta1
Version 4.1.0 rc1
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.2.0
Version 4.2.0 beta1
Version 4.2.0 rc1
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.2.4
Version 4.2.5
Version 4.3.0
Version 4.3.0 rc1
Version 4.3.10
Version 4.3.11
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3.5
Version 4.3.6
Version 4.3.7
Version 4.3.8
Version 4.3.9
Version 4.4.0
Version 4.4.0 beta1
Version 4.4.0 rc1
Version 4.4.0 rc2

References (2)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.