A vulnerability classified as critical has been found in Piwigo 2.3.3. This affects an unknown part of the file upgrade.php. The manipulation of the argument Language leads to path traversal.
This vulnerability is uniquely identified as CVE-2012-2208. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leads to improper access controls.
This vulnerability is known as CVE-2025-2686. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2025-2687. It is possible to launch the attack remotely. Furthermore, there is an exploit available.