Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the file parameter. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7394 is for the issue in the "runshellscript echo.sh" script.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-08-07T10:00:00
Updated: 2024-08-06T17:46:23.468Z
Reserved: 2013-11-10T00:00:00
Link: CVE-2013-6771
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-08-07T11:13:34.377
Modified: 2024-11-21T01:59:40.957
Link: CVE-2013-6771
Redhat
No data.