Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.
| Software | From | Fixed in |
|---|---|---|
| chyrp / chyrp | 2.0 | 2.0.x |
| chyrp / chyrp | 2.1-beta1 | 2.1-beta1.x |
| chyrp / chyrp | 2.1-rc | 2.1-rc.x |
| chyrp / chyrp | - | 2.1.x |
| chyrp / chyrp | 2.1-beta2 | 2.1-beta2.x |