CVE-2013-5107
14.12.2013, 17:21
Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCK_LANG cookie, as demonstrated in a login.index action to index.php.
| Vendor | Product | Version |
|---|---|---|
| rockmongo | rockmongo | 𝑥 ≤ 1.1.5 |
| rockmongo | rockmongo | 1.0 |
| rockmongo | rockmongo | 1.0.1 |
| rockmongo | rockmongo | 1.0.2 |
| rockmongo | rockmongo | 1.0.3 |
| rockmongo | rockmongo | 1.0.4 |
| rockmongo | rockmongo | 1.0.5 |
| rockmongo | rockmongo | 1.0.6 |
| rockmongo | rockmongo | 1.0.7 |
| rockmongo | rockmongo | 1.0.8 |
| rockmongo | rockmongo | 1.0.9 |
| rockmongo | rockmongo | 1.0.10 |
| rockmongo | rockmongo | 1.0.11 |
| rockmongo | rockmongo | 1.0.12 |
| rockmongo | rockmongo | 1.1.1 |
| rockmongo | rockmongo | 1.1.2 |
| rockmongo | rockmongo | 1.1.3 |
| rockmongo | rockmongo | 1.1.4 |
𝑥
= Vulnerable software versions