VYPR

Ajaxplorer

by Ajaxplorer

CVEs (9)

  • CVE-2013-6227Dec 27, 2014
    risk 0.04cvss epss 0.08

    Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute arbitrary code by uploading an executable file, and then accessing this file at a location…

  • CVE-2013-5688Nov 5, 2013
    risk 0.03cvss epss 0.06

    Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload…

  • CVE-2022-40358Sep 23, 2022
    risk 0.00cvss epss 0.01

    An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafted svg file upload.

  • CVE-2013-4267Feb 11, 2020
    risk 0.00cvss epss 0.04

    Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the…

  • CVE-2015-5650Oct 6, 2015
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in AjaXplorer 2.0 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2013-6226Nov 14, 2013
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to read or delete arbitrary files via unspecified vectors.

  • CVE-2012-1840Mar 22, 2012
    risk 0.00cvss epss 0.02

    AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login access by leveraging knowledge of a password hash.

  • CVE-2012-1839Mar 22, 2012
    risk 0.00cvss epss 0.04

    Multiple directory traversal vulnerabilities in the Get Template feature in plugins/gui.ajax/class.AJXP_ClientDriver.php in AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1)…

  • CVE-2008-6639Apr 7, 2009
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action.