← Vulnerability feed

Vulnerability record · CVE-2013-1469 · published 13 March 2013

CVE-2013-1469: Piwigo install.php directory traversal via dl parameter

Piwigo · Piwigo

Piwigo before 2.4.7 contains a directory traversal flaw in install.php. The dl parameter accepts .. sequences, letting a remote attacker read and delete arbitrary files on the server. Because install.php is a setup script, exposure of an unremoved installer is the main risk.

4.0 CVSS 2.0 Medium EPSS 56% · top 1.0% CWE-22 · Path traversal
4.0CVSS 2.0 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 10 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.

AV:N/AC:H/Au:N/C:P/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityPublic exploit code exists and EPSS is very high, but the CVSS v2 score is only 4.0 MEDIUM and exploitation requires the installer to be reachable.

What it is

Piwigo before 2.4.7 contains a directory traversal flaw in install.php. The dl parameter accepts .. sequences, letting a remote attacker read and delete arbitrary files on the server. Because install.php is a setup script, exposure of an unremoved installer is the main risk.

Impact

An attacker can read arbitrary files, exposing configuration or credential material, and delete arbitrary files, which can break the application or remove data. The CVSS v2 vector rates confidentiality and availability impact as partial.

Attack surface

Reachable over the network through HTTP requests to install.php with a crafted dl parameter. The CVSS v2 vector (AV:N/AC:H/Au:N) indicates no authentication is required but exploitation is rated high complexity; no user interaction is described.

Exploitation

Not listed in CISA KEV, but EPSS is 0.56011 (99th percentile) and multiple references are tagged Exploit, including Exploit-DB 24561, so public exploit code exists.

What to do

  • Upgrade Piwigo to 2.4.7 or later.
  • Remove or block access to install.php on production instances.
  • Restrict web server permissions so the Piwigo process cannot delete files outside its data directories.
  • Validate and reject path traversal sequences in any file-handling parameter.
  • Monitor for requests to install.php containing .. in query parameters.

Detection

  • Search web logs for requests to install.php with dl parameters containing ../ or encoded traversal sequences.
  • Alert on HTTP 200 responses from install.php on production hosts.
  • Monitor for unexpected deletion or modification of files outside the Piwigo web root.
  • Check file integrity of Piwigo installation and configuration files for unauthorized changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1469 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2013-1469), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.