CVE-2013-4173: Path Traversal
Published Oct 11, 2013
·Updated
Directory traversal vulnerability in the trend-data daemon (xymondrrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitrary files via a .. (dot dot) in the host name in a "drophost" command.
Affected Software
13 affected components
Xymon xymon<=4.3.1
Xymon xymon=4.0
Xymon xymon=4.0.1
Xymon xymon=4.0.2
Xymon xymon=4.0.3
Xymon xymon=4.0.4
Xymon xymon=4.1.0
Xymon xymon=4.1.1
Xymon xymon=4.1.2
Xymon xymon=4.2.0
Xymon xymon=4.2.2
Xymon xymon=4.2.3
Xymon xymon=4.3.0
Remediation
Patch Available
Event History
Oct 11, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4173?
CVE-2013-4173 has a medium severity rating due to the potential for remote file deletion.
2
How do I fix CVE-2013-4173?
To fix CVE-2013-4173, upgrade to Xymon version 4.3.12 or later where the vulnerability has been patched.
3
What are the affected versions for CVE-2013-4173?
CVE-2013-4173 affects Xymon versions prior to 4.3.12, including all 4.x versions up to 4.3.1.
4
Can CVE-2013-4173 be exploited remotely?
Yes, CVE-2013-4173 can be exploited remotely by attackers using a specially crafted 'drophost' command.
5
What type of vulnerability is CVE-2013-4173?
CVE-2013-4173 is a directory traversal vulnerability that allows unauthorized file deletion.