Vulnerabilities > Extplorer > Extplorer > 2.1.3

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2019-25096 Cross-site Scripting vulnerability in Extplorer
A vulnerability has been found in soerennb eXtplorer up to 2.1.12 and classified as problematic.
network
low complexity
extplorer CWE-79
6.1
2023-01-05 CVE-2019-25097 Path Traversal vulnerability in Extplorer
A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical.
network
low complexity
extplorer CWE-22
critical
9.8
2023-01-05 CVE-2019-25098 Path Traversal vulnerability in Extplorer
A vulnerability was found in soerennb eXtplorer up to 2.1.12.
network
low complexity
extplorer CWE-22
critical
9.8
2017-08-09 CVE-2017-12756 Command Injection vulnerability in Extplorer
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.
network
low complexity
extplorer CWE-77
6.5
2015-10-16 CVE-2015-5660 Cross-Site Request Forgery (CSRF) vulnerability in Extplorer
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.
network
extplorer CWE-352
6.8
2015-03-18 CVE-2015-0896 Cross-site Scripting vulnerability in Extplorer
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
extplorer CWE-79
4.3
2014-03-25 CVE-2013-5951 Cross-Site Scripting vulnerability in Extplorer 2.1.3
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
network
high complexity
extplorer CWE-79
2.6