6.5
CVSSv2

CVE-2013-3969

Published: 01/10/2013 Updated: 02/10/2013
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 up to and including 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.

Vulnerable Product Search on Vulmon Subscribe to Product

mongodb mongodb 2.4.0

mongodb mongodb 2.4.1

mongodb mongodb 2.4.2

mongodb mongodb 2.4.3

mongodb mongodb 2.4.4

Vendor Advisories

The find prototype in scripting/engine_v8h in MongoDB 240 through 244 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object ...

Exploits

source: wwwsecurityfocuscom/bid/61309/info MongoDB is prone to a remote code execution vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability to execute arbitrary code within the context of the affected application MongoDB 244 is vulnerable; other versions may also be affec ...