Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2013-2068Path Traversal in Redhat Cloudforms Management Engine

Severity
9.4CRITICALNVD
EPSS
78.5%
top 0.96%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedSep 28
Latest updateMay 17

Description

Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.

CVSS vector

AV:N/AC:L/C:N/I:C/A:CExploitability: 10.0 | Impact: 9.2

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-ggp4-2h22-73vm: Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 22022-05-17
CVEList
CVE-2013-2068: Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 22013-09-28

💥Exploits & PoCs

1
Exploit-DB
RedHat CloudForms Management Engine 5.1 - agent/linuxpkgs Directory Traversal (Metasploit)2013-12-24

📋Vendor Advisories

1
Red Hat
cfme: CFME 2.0 multiple zip file upload path traversal vulnerabilities2013-09-04

💬Community

1
Bugzilla
CVE-2013-2068 cfme: CFME 2.0 multiple zip file upload path traversal vulnerabilities2013-05-07
CVE-2013-2068 — Path Traversal in Redhat | cvebase