2.6
CVSSv2

CVE-2013-5951

Published: 25/03/2014 Updated: 31/12/2016
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.

Vulnerable Product Search on Vulmon Subscribe to Product

extplorer extplorer 2.1.3

Vendor Advisories

Multiple cross-site scripting (XSS) vulnerabilities have been discovered in extplorer, a web file explorer and manager using Ext JS A remote attacker can inject arbitrary web script or HTML code via a crafted string in the URL to applicationjsphp, adminphp, copy_movephp, functionsphp, headerphp and uploadphp For the oldstable distribution ...