Vulnerabilities > Extplorer > Extplorer > 2.0.0

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2019-25096 Cross-site Scripting vulnerability in Extplorer
A vulnerability has been found in soerennb eXtplorer up to 2.1.12 and classified as problematic.
network
low complexity
extplorer CWE-79
6.1
2023-01-05 CVE-2019-25097 Path Traversal vulnerability in Extplorer
A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical.
network
low complexity
extplorer CWE-22
critical
9.8
2023-01-05 CVE-2019-25098 Path Traversal vulnerability in Extplorer
A vulnerability was found in soerennb eXtplorer up to 2.1.12.
network
low complexity
extplorer CWE-22
critical
9.8
2020-04-10 CVE-2019-7305 Files or Directories Accessible to External Parties vulnerability in Extplorer 2.0.0/2.1.0
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP.
network
low complexity
extplorer CWE-552
7.5
2018-10-07 CVE-2012-6710 Improper Authentication vulnerability in Extplorer
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.
network
low complexity
extplorer CWE-287
7.5
2017-08-09 CVE-2017-12756 Command Injection vulnerability in Extplorer
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.
network
low complexity
extplorer CWE-77
6.5
2015-10-16 CVE-2015-5660 Cross-Site Request Forgery (CSRF) vulnerability in Extplorer
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.
network
extplorer CWE-352
6.8
2015-03-18 CVE-2015-0896 Cross-site Scripting vulnerability in Extplorer
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
extplorer CWE-79
4.3
2012-07-12 CVE-2012-3362 Cross-Site Request Forgery (CSRF) vulnerability in Extplorer 2.0.0/2.1.0
Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.
network
extplorer CWE-352
6.8