8.5
CVSSv2

CVE-2013-6226

Published: 14/11/2013 Updated: 14/02/2024
CVSS v2 Base Score: 8.5 | Impact Score: 7.8 | Exploitability Score: 10
VMScore: 756
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:P

Vulnerability Summary

Directory traversal vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) prior to 5.0.4 allows remote malicious users to read or delete arbitrary files via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

ajaxplorer ajaxplorer 3.1.1

ajaxplorer ajaxplorer 2.5

ajaxplorer ajaxplorer 3.3.2

ajaxplorer ajaxplorer 3.0.1

ajaxplorer ajaxplorer 4.2.3

ajaxplorer ajaxplorer 4.0.4

ajaxplorer ajaxplorer 3.3.4

ajaxplorer ajaxplorer 5.0.1

ajaxplorer ajaxplorer 3.0

ajaxplorer ajaxplorer 2.7.2

ajaxplorer ajaxplorer 3.1

ajaxplorer ajaxplorer 3.2.3

ajaxplorer ajaxplorer 2.6.0

ajaxplorer ajaxplorer 2.5.4

ajaxplorer ajaxplorer 4.2.2

ajaxplorer ajaxplorer 2.3.3

ajaxplorer ajaxplorer 5.0.2

ajaxplorer ajaxplorer 3.2.1

ajaxplorer ajaxplorer 3.2.5

ajaxplorer ajaxplorer

ajaxplorer ajaxplorer 4.0.3

ajaxplorer ajaxplorer 2.3.4

ajaxplorer ajaxplorer 3.0.3

ajaxplorer ajaxplorer 2.7.1

ajaxplorer ajaxplorer 3.2.2

ajaxplorer ajaxplorer 3.3.5

ajaxplorer ajaxplorer 4.0

ajaxplorer ajaxplorer 2.7.3

ajaxplorer ajaxplorer 3.2

ajaxplorer ajaxplorer 5.0.0

ajaxplorer ajaxplorer 3.3.3

ajaxplorer ajaxplorer 4.0.2

ajaxplorer ajaxplorer 3.2.4

ajaxplorer ajaxplorer 3.0.2

ajaxplorer ajaxplorer 4.0.1

ajaxplorer ajaxplorer 4.2.0

ajaxplorer ajaxplorer 2.5.5

Exploits

Pydio / AjaXplorer versions 503 and below suffer from an unrestricted upload functionality that allows for remote code execution ...