CVE-2013-5107

Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCK_LANG cookie, as demonstrated in a login.index action to index.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
rockmongorockmongo
𝑥
≤ 1.1.5
rockmongorockmongo
1.0
rockmongorockmongo
1.0.1
rockmongorockmongo
1.0.2
rockmongorockmongo
1.0.3
rockmongorockmongo
1.0.4
rockmongorockmongo
1.0.5
rockmongorockmongo
1.0.6
rockmongorockmongo
1.0.7
rockmongorockmongo
1.0.8
rockmongorockmongo
1.0.9
rockmongorockmongo
1.0.10
rockmongorockmongo
1.0.11
rockmongorockmongo
1.0.12
rockmongorockmongo
1.1.1
rockmongorockmongo
1.1.2
rockmongorockmongo
1.1.3
rockmongorockmongo
1.1.4
𝑥
= Vulnerable software versions