CyberSec.Space Logo
Back to CVE Browser

CVE-2013-7091

MEDIUM
5.0
CVSS Severity Score
EPSS Score0.1580%
EPSS Percentile38.15th
PublishedDec 13, 2013
Last ModifiedApr 29, 2026

Vulnerability Description

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

Affected Platforms (CPE)

πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.0
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.1
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.2
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.3
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.4
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.5
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.6
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.7
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.8
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.9
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.10
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.12
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.13
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.14
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.15
πŸ“¦
Synacor

Zimbra Collaboration Suite

= 6.0.16

References & Advisories

Related Vulnerabilities