CyberSec.Space Logo
CVEブラウザに戻る

CVE-2013-7091

MEDIUM
5.0
CVSS Severity Score
EPSS Score0.1580%
EPSS Percentile38.15th
Published2013年12月13日
Last Modified2026年4月29日

Vulnerability Description

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

Affected Platforms (CPE)

📦
Synacor

Zimbra Collaboration Suite

= 6.0.0
📦
Synacor

Zimbra Collaboration Suite

= 6.0.1
📦
Synacor

Zimbra Collaboration Suite

= 6.0.2
📦
Synacor

Zimbra Collaboration Suite

= 6.0.3
📦
Synacor

Zimbra Collaboration Suite

= 6.0.4
📦
Synacor

Zimbra Collaboration Suite

= 6.0.5
📦
Synacor

Zimbra Collaboration Suite

= 6.0.6
📦
Synacor

Zimbra Collaboration Suite

= 6.0.7
📦
Synacor

Zimbra Collaboration Suite

= 6.0.8
📦
Synacor

Zimbra Collaboration Suite

= 6.0.9
📦
Synacor

Zimbra Collaboration Suite

= 6.0.10
📦
Synacor

Zimbra Collaboration Suite

= 6.0.12
📦
Synacor

Zimbra Collaboration Suite

= 6.0.13
📦
Synacor

Zimbra Collaboration Suite

= 6.0.14
📦
Synacor

Zimbra Collaboration Suite

= 6.0.15
📦
Synacor

Zimbra Collaboration Suite

= 6.0.16

References & Advisories

関連する脆弱性情報