CVE-2013-6618
Summary
| CVE | CVE-2013-6618 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-11-05 20:55:30 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Juniper | Junos | 10.0 | All | All | All |
| Operating System | Juniper | Junos | 10.1 | All | All | All |
| Operating System | Juniper | Junos | 10.2 | All | All | All |
| Operating System | Juniper | Junos | 10.3 | All | All | All |
| Operating System | Juniper | Junos | 11.4 | All | All | All |
| Operating System | Juniper | Junos | 12.1 | All | All | All |
| Operating System | Juniper | Junos | 12.2 | All | All | All |
| Operating System | Juniper | Junos | 12.3 | All | All | All |
| Operating System | Juniper | Junos | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sense of Security - Security Advisory - SOS-13-003 - Juniper Junos J-Web Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.senseofsecurity.com.au | Exploit, URL Repurposed |
| Juniper Junos J-Web '/jsdm/ajax/port.php' Script Lets Remote Authenticated Users Execute Arbitrary Commands - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Juniper Junos J-Web Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Juniper Junos J-Web - Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Juniper Networks - 2013-04 Security Bulletin: Junos: J-Web Sajax remote code execution - Knowledge Base | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.