← Back

CVE-2013-4173

nvd nist
Published: Oct 11, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitrary files via a .. (dot dot) in the host name in a "drophost" command.

Affected (13)

Products: Xymon: Xymon
1 product
Xymon
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Xymon
Up to 4.3.1
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0
Version 4.1.0
Version 4.1.1
Version 4.1.2
Version 4.2.0
Version 4.2.2
Version 4.2.3
Version 4.3.0

References (6)

Timeline

No history available yet.