{"id":"CVE-2014-1836","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-1836","summary":"ImpressCMS Path Traversal to Arbitrary File Delete","details":"Absolute path traversal vulnerability in `htdocs/libraries/image-editor/image-edit.php` in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the `image_path` parameter in a cancel action.","published":"2022-05-17T04:12:03Z","modified":"2023-11-08T03:57:35.126843Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"impresscms/impresscms","fixedVersion":"1.3.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-1836"},{"type":"WEB","url":"https://github.com/ImpressCMS/impresscms/issues/914"},{"type":"WEB","url":"https://github.com/pedrib/PoC/blob/master/generic/impresscms-1.3.5.txt"},{"type":"WEB","url":"https://web.archive.org/web/20200228234251/http://www.securityfocus.com/bid/65279"},{"type":"WEB","url":"http://community.impresscms.org/modules/smartsection/item.php?itemid=675"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2014/Feb/14"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:35.126843Z"}}