CVE-2013-7091: Path Traversal
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7091?
CVE-2013-7091 is considered a moderate severity vulnerability that allows directory traversal attacks.
How do I fix CVE-2013-7091?
To fix CVE-2013-7091, you should update Zimbra Collaboration Suite to the latest version that addresses this vulnerability.
What versions of Zimbra are affected by CVE-2013-7091?
CVE-2013-7091 affects Zimbra Collaboration Suite versions 6.0.0 through 6.0.16, as well as versions 7.2.2 and 8.0.2.
What impact does CVE-2013-7091 have on my system?
CVE-2013-7091 can allow remote attackers to read arbitrary files from the server, possibly leading to further exploitation.
Can CVE-2013-7091 be leveraged for remote code execution?
Yes, CVE-2013-7091 can potentially be exploited to execute arbitrary code by reading sensitive files.