Vulnerabilities > CVE-2019-7305 - Files or Directories Accessible to External Parties vulnerability in Extplorer 1.0.0/2.0.0/2.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 20 | |
OS | 1 | |
OS | 1 |