5.5
CVSSv2

CVE-2013-5688

Published: 05/11/2013 Updated: 06/11/2013
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 555
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and previous versions allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the dir parameter in an upload action.

Vulnerable Product Search on Vulmon Subscribe to Product

ajaxplorer ajaxplorer 4.0.4

ajaxplorer ajaxplorer 3.2

ajaxplorer ajaxplorer 3.1.1

ajaxplorer ajaxplorer 3.1

ajaxplorer ajaxplorer 3.0.3

ajaxplorer ajaxplorer 5.0.1

ajaxplorer ajaxplorer 5.0.0

ajaxplorer ajaxplorer 4.2.3

ajaxplorer ajaxplorer 4.2.2

ajaxplorer ajaxplorer 3.3.4

ajaxplorer ajaxplorer 3.3.3

ajaxplorer ajaxplorer 3.3.2

ajaxplorer ajaxplorer 3.2.5

ajaxplorer ajaxplorer 2.7.2

ajaxplorer ajaxplorer 2.7.1

ajaxplorer ajaxplorer 2.6.0

ajaxplorer ajaxplorer 2.5.5

ajaxplorer ajaxplorer 4.0.3

ajaxplorer ajaxplorer 4.0.1

ajaxplorer ajaxplorer 3.3.5

ajaxplorer ajaxplorer 3.2.4

ajaxplorer ajaxplorer 3.2.2

ajaxplorer ajaxplorer 3.0.1

ajaxplorer ajaxplorer 2.7.3

ajaxplorer ajaxplorer 2.5.4

ajaxplorer ajaxplorer 2.3.4

ajaxplorer ajaxplorer

ajaxplorer ajaxplorer 4.2.0

ajaxplorer ajaxplorer 4.0.2

ajaxplorer ajaxplorer 4.0

ajaxplorer ajaxplorer 3.2.3

ajaxplorer ajaxplorer 3.2.1

ajaxplorer ajaxplorer 3.0.2

ajaxplorer ajaxplorer 3.0

ajaxplorer ajaxplorer 2.5

ajaxplorer ajaxplorer 2.3.3

Exploits

Trustwave SpiderLabs Security Advisory TWSL2013-027: Multiple Vulnerabilities in AjaXplorer Published: 09/05/13 Version: 10 Vendor: AjaXplorer (ajaxplorerinfo) Product: AjaXplorer Version affected: 502 and prior Product description: AjaXplorer is an open source file sharing platform which relies on PHP and the web interface can run on ...
AjaXplorer versions 502 and below suffer from remote shell upload and path traversal vulnerabilities ...