CVE-2013-6771
Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitr
Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the file parameter. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types.
CVE-2013-7394 is for the issue in the "runshellscript echo.sh" script.
HIGH · CVSS 9.3
EPSS 0.04064
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0