Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian
2020-04-10T00:15:11.347
2024-11-21T04:47:58.170
Modified
CVSSv3.1: 5.8 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | extplorer | extplorer | ≤ 2.1.0 | Yes |
Operating System | canonical | ubuntu_linux | - | No |
Operating System | debian | debian_linux | - | No |