PT-2013-5366 · Rockmongo · Rockmongo

Published

2013-12-14

·

Updated

2013-12-16

·

CVE-2013-5107

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions RockMongo versions 1.1.5 and earlier
Description The issue allows remote attackers to read arbitrary files by exploiting a directory traversal vulnerability. This can be achieved by including a .. (dot dot) in the ROCK LANG cookie, as seen in a login.index action to "index.php".
Recommendations For RockMongo versions 1.1.5 and earlier, consider restricting access to the ROCK LANG cookie to minimize the risk of exploitation until a patch is available. Avoid using the ROCK LANG cookie with untrusted input in the "index.php" endpoint.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5107

Affected Products

Rockmongo