VYPR

Dext5.ocx

by Dext5

CVEs (5)

  • CVE-2020-35362Dec 26, 2020
    risk 0.00cvss epss 0.00

    DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct…

  • CVE-2020-13442May 25, 2020
    risk 0.00cvss epss 0.03

    A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.

  • CVE-2019-19164May 7, 2020
    risk 0.00cvss epss 0.00

    dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remote files to be executed by setting the arguments to the activex method. A remote attacker could induce a user to access a crafted web page, causing damage such…

  • CVE-2019-19168May 6, 2020
    risk 0.00cvss epss 0.01

    Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.

  • CVE-2019-19169May 6, 2020
    risk 0.00cvss epss 0.01

    Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.