eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExtplorer
APPExtplorer2.1.15
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2023-54335CRITICAL9.3PL ✓same product
Authentication bypass i RCE w eXtplorer 2.1.14
CVE-2012-6710CRITICAL9.8PL ✓same product
eXtplorer — pominięcie uwierzytelnienia przez pustą tablicę hasła
CVE-2023-27842HIGH8.8same product
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker...
CVE-2017-12756HIGH7.2same product
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command ...
CVE-2016-4313HIGH7.8same product
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execu...