CVE-2013-7091

EXPLOITED NUCLEI

Zimbra 7.2.2-8.0.2 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-7091 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including Metasploit, rubina119, including a Metasploit module exploits/unix/webapp/zimbra_lfi. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits a local file inclusion (LFI) vulnerability in Zimbra Collaboration Server to steal LDAP credentials, obtain an admin auth token, and achieve remote code execution via file upload.

Description

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappslinux
https://www.exploit-db.com/exploits/30472

This Metasploit module exploits a local file inclusion (LFI) vulnerability in Zimbra Collaboration Server to steal LDAP credentials, obtain an admin auth token, and achieve remote code execution via file upload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Server 8.0.2 and 7.2.2
No auth needed
Prerequisites: Network access to the Zimbra server · LFI vulnerability in the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by rubina119 · textwebappslinux
https://www.exploit-db.com/exploits/30085

This exploit leverages a Local File Inclusion (LFI) vulnerability in Zimbra to read the localconfig.xml file, which contains LDAP credentials. These credentials are then used to create an admin user via the admin SOAP API, granting administrative access.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Zimbra (versions 2009-early 2013)
No auth needed
Prerequisites: Admin console port (7071) must be open · Target must be vulnerable to LFI
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by rubina119 · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/zimbra_lfi.rb

This Metasploit module exploits a local file inclusion (LFI) vulnerability in Zimbra Collaboration Server to steal LDAP credentials, obtain an admin auth token, and achieve remote code execution via file upload and JSP stager execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Server 8.0.2 and 7.2.2
No auth needed
Prerequisites: Network access to the Zimbra admin interface · LFI vulnerability in the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion
MEDIUMby rubina119
Shodan: http.title:"zimbra collaboration suite" || http.title:"zimbra web client sign in"
FOFA: title="zimbra web client sign in" || title="zimbra collaboration suite"

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64149
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/124321
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/30472
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/100747
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/30085
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/89527

Scores

EPSS 0.9241
EPSS Percentile 99.7%

Details

VulnCheck KEV 2023-11-13
CWE
CWE-22
Status published
Products (16)
synacor/zimbra_collaboration_suite 6.0.0
synacor/zimbra_collaboration_suite 6.0.1
synacor/zimbra_collaboration_suite 6.0.2
synacor/zimbra_collaboration_suite 6.0.3
synacor/zimbra_collaboration_suite 6.0.4
synacor/zimbra_collaboration_suite 6.0.5
synacor/zimbra_collaboration_suite 6.0.6
synacor/zimbra_collaboration_suite 6.0.7
synacor/zimbra_collaboration_suite 6.0.8
synacor/zimbra_collaboration_suite 6.0.9
... and 6 more
Published Dec 13, 2013
Tracked Since Feb 18, 2026