Vulnerabilities > Extplorer > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-03-25 | CVE-2013-5951 | Cross-Site Scripting vulnerability in Extplorer 2.1.3 Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/. | 2.6 |
2012-08-07 | CVE-2012-3454 | Permissions, Privileges, and Access Controls vulnerability in Extplorer 2.1.0 eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files. | 3.6 |