Vulnerabilities > Extplorer > Extplorer > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-14 | CVE-2023-40628 | Cross-site Scripting vulnerability in Extplorer A reflected XSS vulnerability was discovered in the Extplorer component for Joomla. | 6.1 |
2023-01-05 | CVE-2019-25096 | Cross-site Scripting vulnerability in Extplorer A vulnerability has been found in soerennb eXtplorer up to 2.1.12 and classified as problematic. | 6.1 |
2017-08-09 | CVE-2017-12756 | Command Injection vulnerability in Extplorer Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter. | 6.5 |
2017-04-24 | CVE-2016-4313 | Path Traversal vulnerability in Extplorer 2.1.9 Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. | 6.8 |
2015-10-16 | CVE-2015-5660 | Cross-Site Request Forgery (CSRF) vulnerability in Extplorer Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code. | 6.8 |
2015-03-18 | CVE-2015-0896 | Cross-site Scripting vulnerability in Extplorer Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |
2012-07-12 | CVE-2012-3362 | Cross-Site Request Forgery (CSRF) vulnerability in Extplorer 2.0.0/2.1.0 Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action. | 6.8 |