CVE-2013-3739
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
05/06/2014
Last modified:
12/04/2025
Description
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the mapname parameter in a show_config action.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:network-weathermap:.network_weathermap:*:c:*:*:*:*:*:* | 0.97 (including) | |
| cpe:2.3:a:network-weathermap:.network_weathermap:0.97:a:*:*:*:*:*:* | ||
| cpe:2.3:a:network-weathermap:.network_weathermap:0.97:b:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2013-06/0035.html
- http://osvdb.org/94078
- http://www.exploit-db.com/exploits/26125
- http://www.securityfocus.com/bid/60434
- http://archives.neohapsis.com/archives/bugtraq/2013-06/0035.html
- http://osvdb.org/94078
- http://www.exploit-db.com/exploits/26125
- http://www.securityfocus.com/bid/60434



