Vulnerabilities > Extplorer > Extplorer

DATE CVE VULNERABILITY TITLE RISK
2015-10-16 CVE-2015-5660 Cross-Site Request Forgery (CSRF) vulnerability in Extplorer
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.
network
extplorer CWE-352
6.8
2015-03-18 CVE-2015-0896 Cross-site Scripting vulnerability in Extplorer
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
extplorer CWE-79
4.3
2014-03-25 CVE-2013-5951 Cross-Site Scripting vulnerability in Extplorer 2.1.3
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
network
high complexity
extplorer CWE-79
2.6
2012-08-07 CVE-2012-3454 Permissions, Privileges, and Access Controls vulnerability in Extplorer 2.1.0
eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files.
local
low complexity
extplorer CWE-264
3.6
2012-07-12 CVE-2012-3362 Cross-Site Request Forgery (CSRF) vulnerability in Extplorer 2.0.0/2.1.0
Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.
network
extplorer CWE-352
6.8