CVE-2013-7091 Scanner

Detects 'Directory Traversal' vulnerability in Zimbra affects v. 7.2.2 and 8.0.2.


Zimbra is an enterprise-level email and collaboration solution designed for organizations of various sizes. This platform provides email, contacts, calendar, and task management features through a web-based interface. It is a popular software due to its ease of use, features, and how it integrates with other business software. Zimbra can be integrated with Microsoft Exchange and other popular email providers.

CVE-2013-7091 is a directory traversal vulnerability in the /res/I18nMsg directory of Zimbra. It allows remote attackers to read arbitrary files using ".." in the skin parameter. This vulnerability was detected on Zimbra 7.2.2 and 8.0.2 versions. An attacker can exploit this vulnerability by obtaining data from LDAP credentials and accessing the service/admin/soap API.

Exploiting CVE-2013-7091 can have significant consequences for an organization. An attacker can use this vulnerability to obtain sensitive information such as usernames, passwords, and other confidential data. With access to the service/admin/soap API, an attacker can execute arbitrary code and harm the organization's systems and data.

