Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2015-5660
Disclosure Date: October 16, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.
0
Attacker Value
Unknown
CVE-2015-0896
Disclosure Date: March 18, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-5951
Disclosure Date: March 25, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
0
Attacker Value
Unknown
CVE-2012-3454
Disclosure Date: August 07, 2012 (last updated October 04, 2023)
eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files.
0
Attacker Value
Unknown
CVE-2012-3362
Disclosure Date: July 12, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.
0
Attacker Value
Unknown
CVE-2008-4764
Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.
0