Vulnerability record · CVE-2013-1469 · published 13 March 2013
CVE-2013-1469: Piwigo install.php directory traversal via dl parameter
Piwigo · Piwigo
Piwigo before 2.4.7 contains a directory traversal flaw in install.php. The dl parameter accepts .. sequences, letting a remote attacker read and delete arbitrary files on the server. Because install.php is a setup script, exposure of an unremoved installer is the main risk.
Description
Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.
AV:N/AC:H/Au:N/C:P/I:N/A:P
Automated analysis
high priorityPublic exploit code exists and EPSS is very high, but the CVSS v2 score is only 4.0 MEDIUM and exploitation requires the installer to be reachable.
What it is
Piwigo before 2.4.7 contains a directory traversal flaw in install.php. The dl parameter accepts .. sequences, letting a remote attacker read and delete arbitrary files on the server. Because install.php is a setup script, exposure of an unremoved installer is the main risk.
Impact
An attacker can read arbitrary files, exposing configuration or credential material, and delete arbitrary files, which can break the application or remove data. The CVSS v2 vector rates confidentiality and availability impact as partial.
Attack surface
Reachable over the network through HTTP requests to install.php with a crafted dl parameter. The CVSS v2 vector (AV:N/AC:H/Au:N) indicates no authentication is required but exploitation is rated high complexity; no user interaction is described.
Exploitation
Not listed in CISA KEV, but EPSS is 0.56011 (99th percentile) and multiple references are tagged Exploit, including Exploit-DB 24561, so public exploit code exists.
What to do
- Upgrade Piwigo to 2.4.7 or later.
- Remove or block access to install.php on production instances.
- Restrict web server permissions so the Piwigo process cannot delete files outside its data directories.
- Validate and reject path traversal sequences in any file-handling parameter.
- Monitor for requests to install.php containing .. in query parameters.
Detection
- Search web logs for requests to install.php with dl parameters containing ../ or encoded traversal sequences.
- Alert on HTTP 200 responses from install.php on production hosts.
- Monitor for unexpected deletion or modification of files outside the Piwigo web root.
- Check file integrity of Piwigo installation and configuration files for unauthorized changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1469 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1469), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.