CVE-2013-5107
14.12.2013, 17:21
Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCK_LANG cookie, as demonstrated in a login.index action to index.php.
Vendor | Product | Version |
---|---|---|
rockmongo | rockmongo | 𝑥 ≤ 1.1.5 |
rockmongo | rockmongo | 1.0 |
rockmongo | rockmongo | 1.0.1 |
rockmongo | rockmongo | 1.0.2 |
rockmongo | rockmongo | 1.0.3 |
rockmongo | rockmongo | 1.0.4 |
rockmongo | rockmongo | 1.0.5 |
rockmongo | rockmongo | 1.0.6 |
rockmongo | rockmongo | 1.0.7 |
rockmongo | rockmongo | 1.0.8 |
rockmongo | rockmongo | 1.0.9 |
rockmongo | rockmongo | 1.0.10 |
rockmongo | rockmongo | 1.0.11 |
rockmongo | rockmongo | 1.0.12 |
rockmongo | rockmongo | 1.1.1 |
rockmongo | rockmongo | 1.1.2 |
rockmongo | rockmongo | 1.1.3 |
rockmongo | rockmongo | 1.1.4 |
𝑥
= Vulnerable software versions