HIGH🇵🇱 Wersja polska

CVE-2017-12756

CVSS 7.2v3.0pub. 2017-08-09upd. 2026-05-13

Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Extplorer

    APP
    Extplorer
    ≤ 2.1.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-54335CRITICAL9.3PL ✓same product

Authentication bypass i RCE w eXtplorer 2.1.14

CVE-2012-6710CRITICAL9.8PL ✓same product

eXtplorer — pominięcie uwierzytelnienia przez pustą tablicę hasła

CVE-2023-29657HIGH8.8same product

eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file ...

CVE-2023-27842HIGH8.8same product

Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker...

CVE-2016-4313HIGH7.8same product

Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execu...