Vulnerabilities > Extplorer > Extplorer > 2.0.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-01-05 | CVE-2019-25096 | Cross-site Scripting vulnerability in Extplorer A vulnerability has been found in soerennb eXtplorer up to 2.1.12 and classified as problematic. | 6.1 |
2023-01-05 | CVE-2019-25097 | Unspecified vulnerability in Extplorer A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. | 9.8 |
2023-01-05 | CVE-2019-25098 | Path Traversal vulnerability in Extplorer A vulnerability was found in soerennb eXtplorer up to 2.1.12. | 9.8 |
2020-04-10 | CVE-2019-7305 | Files or Directories Accessible to External Parties vulnerability in Extplorer 1.0.0/2.0.0/2.1.0 Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. | 9.8 |
2018-10-07 | CVE-2012-6710 | Improper Authentication vulnerability in Extplorer ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php. | 9.8 |
2017-08-09 | CVE-2017-12756 | Command Injection vulnerability in Extplorer Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter. | 7.2 |