7.5
CVSSv2

CVE-2011-5005

Published: 25/12/2011 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in QuiXplorer 2.3 and previous versions allows remote malicious users to execute arbitrary code by uploading a file with an executable extension using the upload action to index.php, then accessing it via a direct request to the file in an unspecified directory.

Vulnerable Product Search on Vulmon Subscribe to Product

mads brunn t3quixplorer 1.7.0

claudio klingler quixplorer 1.6

claudio klingler quixplorer 1.1

mads brunn t3quixplorer 1.2.0

mads brunn t3quixplorer 1.6.0

claudio klingler quixplorer 2.0

claudio klingler quixplorer 1.2

mads brunn t3quixplorer 1.5.0

mads brunn t3quixplorer 1.0.0

claudio klingler quixplorer 1.4

mads brunn t3quixplorer 1.7.1

mads brunn t3quixplorer 1.4.0

claudio klingler quixplorer 1.0

mads brunn t3quixplorer 1.0.2

mads brunn t3quixplorer 1.0.1

claudio klingler quixplorer 1.5

mads brunn t3quixplorer 1.3.0

claudio klingler quixplorer 2.2

claudio klingler quixplorer 2.1.1

claudio klingler quixplorer

Exploits

# Exploit Title: QuiXplorer 23 <= Bugtraq File Upload Vulnerability # Google Dork: "QuiXplorer 23 - the QuiX project" # Date: 13/11/2011 # Author: PCA & krhr_krhr and # Software Link: quixplorersourceforgenet/ # Version: QuiXplorer 23 # Tested on: linux ,windows # CVE : --------------------------------------------------------- ...