9.3
CVSSv2

CVE-2013-6771

Published: 07/08/2014 Updated: 07/08/2014
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in the collect script in Splunk prior to 5.0.5 allows remote malicious users to execute arbitrary commands via a .. (dot dot) in the file parameter. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7394 is for the issue in the "runshellscript echo.sh" script.

Vulnerable Product Search on Vulmon Subscribe to Product

splunk splunk

splunk splunk 5.0.3

splunk splunk 5.0.2

splunk splunk 5.0.1

splunk splunk 5.0