Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2015-5660

Disclosure Date: October 16, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.
0
Attacker Value
Unknown

CVE-2015-0896

Disclosure Date: March 18, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-5951

Disclosure Date: March 25, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
0
Attacker Value
Unknown

CVE-2012-3454

Disclosure Date: August 07, 2012 (last updated October 04, 2023)
eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files.
0
Attacker Value
Unknown

CVE-2012-3362

Disclosure Date: July 12, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.
0
Attacker Value
Unknown

CVE-2008-4764

Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.
0