← All CVEs

CVE-2013-7091

medium · 5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

5
CVSS
86.3%
EPSS (exploit prob.)
100th
EPSS percentile
2013-12-13
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
synacorzimbra_collaboration_suite6.0.0
synacorzimbra_collaboration_suite6.0.1
synacorzimbra_collaboration_suite6.0.2
synacorzimbra_collaboration_suite6.0.3
synacorzimbra_collaboration_suite6.0.4
synacorzimbra_collaboration_suite6.0.5
synacorzimbra_collaboration_suite6.0.6
synacorzimbra_collaboration_suite6.0.7
synacorzimbra_collaboration_suite6.0.8
synacorzimbra_collaboration_suite6.0.9
synacorzimbra_collaboration_suite6.0.10
synacorzimbra_collaboration_suite6.0.12
synacorzimbra_collaboration_suite6.0.13
synacorzimbra_collaboration_suite6.0.14
synacorzimbra_collaboration_suite6.0.15
synacorzimbra_collaboration_suite6.0.16

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-7091