High severity7.5NVD Advisory· Published May 9, 2019· Updated Jun 17, 2026
CVE-2017-12761
CVE-2017-12761
Description
http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.php?id=WebExplorer/../config.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:webfile_explorer_project:webfile_explorer:1.0:*:*:*:*:*:*:*
- Endober/WebFile Explorerdescription
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/42440nvdExploitThird Party AdvisoryVDB Entry
- codecanyon.net/user/EndobernvdNot ApplicableThird Party Advisory
- speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.phpnvdBroken LinkThird Party Advisory
- webfile.comnvdThird Party Advisory
News mentions
0No linked articles in our index yet.