Vulnerabilities > CVE-2009-1314 - Remote Security vulnerability in Webfileexplorer web File Explorer 3.1

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
webfileexplorer
critical
exploit available

Summary

body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.

Vulnerable Configurations

Part Description Count
Application
Webfileexplorer
1

Exploit-Db

descriptionWebFileExplorer 3.1 (Auth Bypass) SQL Injection Vulnerability. CVE-2009-1314,CVE-2009-1323. Webapps exploit for php platform
fileexploits/php/webapps/8382.txt
idEDB-ID:8382
last seen2016-02-01
modified2009-04-09
platformphp
port
published2009-04-09
reporterOsirys
sourcehttps://www.exploit-db.com/download/8382/
titleWebFileExplorer 3.1 Auth Bypass SQL Injection Vulnerability
typewebapps