Vulnerabilities > Extplorer > Low

DATE CVE VULNERABILITY TITLE RISK
2014-03-25 CVE-2013-5951 Cross-Site Scripting vulnerability in Extplorer 2.1.3
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
network
high complexity
extplorer CWE-79
2.6
2012-08-07 CVE-2012-3454 Permissions, Privileges, and Access Controls vulnerability in Extplorer 2.1.0
eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files.
local
low complexity
extplorer CWE-264
3.6