CVE-2013-5107: Path Traversal
Published Dec 14, 2013
·Updated
Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCKLANG cookie, as demonstrated in a login.index action to index.php.
Affected Software
18 affected components
RockMongo RockMongo<=1.1.5
RockMongo RockMongo=1.0
RockMongo RockMongo=1.0.1
RockMongo RockMongo=1.0.2
RockMongo RockMongo=1.0.3
RockMongo RockMongo=1.0.4
RockMongo RockMongo=1.0.5
RockMongo RockMongo=1.0.6
RockMongo RockMongo=1.0.7
RockMongo RockMongo=1.0.8
RockMongo RockMongo=1.0.9
RockMongo RockMongo=1.0.10
RockMongo RockMongo=1.0.11
RockMongo RockMongo=1.0.12
RockMongo RockMongo=1.1.1
RockMongo RockMongo=1.1.2
RockMongo RockMongo=1.1.3
RockMongo RockMongo=1.1.4
Event History
Dec 14, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5107?
CVE-2013-5107 is classified as a high severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2013-5107?
To fix CVE-2013-5107, it is recommended to upgrade RockMongo to version 1.1.6 or later, where this vulnerability has been addressed.
3
What type of vulnerability is CVE-2013-5107?
CVE-2013-5107 is a directory traversal vulnerability that allows remote attackers to read arbitrary files.
4
Which versions of RockMongo are affected by CVE-2013-5107?
All versions of RockMongo up to and including 1.1.5 are affected by CVE-2013-5107.
5
Can CVE-2013-5107 be exploited remotely?
Yes, CVE-2013-5107 can be exploited remotely through manipulated inputs in the ROCK_LANG cookie.