CVE-2013-5107

EUVD-2013-4948
Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCK_LANG cookie, as demonstrated in a login.index action to index.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
rockmongorockmongo
𝑥
≤ 1.1.5
rockmongorockmongo
1.0
rockmongorockmongo
1.0.1
rockmongorockmongo
1.0.2
rockmongorockmongo
1.0.3
rockmongorockmongo
1.0.4
rockmongorockmongo
1.0.5
rockmongorockmongo
1.0.6
rockmongorockmongo
1.0.7
rockmongorockmongo
1.0.8
rockmongorockmongo
1.0.9
rockmongorockmongo
1.0.10
rockmongorockmongo
1.0.11
rockmongorockmongo
1.0.12
rockmongorockmongo
1.1.1
rockmongorockmongo
1.1.2
rockmongorockmongo
1.1.3
rockmongorockmongo
1.1.4
𝑥
= Vulnerable software versions