Записи Extplorer
18 опубликованных записей вендора extplorer.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 5,6 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-287 Improper Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2012-6710Готовый эксплойт | ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an actioextplorer · extplorer · CWE-287 | Критическая9,8 | — | 25,0 % | 7 окт. 2018 г. |
40В плане | CVE-2019-7305Эксплойта нет | eXtplorer exposes /usr and /etc/extplorer over HTTPextplorer · extplorer · CWE-200 | Критическая9,8 | — | 1,8 % | 9 апр. 2020 г. |
39Наблюдать | CVE-2023-54335Эксплойта нет | eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)extplorer · extplorer · CWE-306 | Критическая9,3 | — | 5,8 % | 13 янв. 2026 г. |
39Наблюдать | CVE-2019-25097Эксплойта нет | soerennb eXtplorer Directory Content path traversalextplorer · extplorer · CWE-22 | Критическая9,8 | — | 1,0 % | 5 янв. 2023 г. |
39Наблюдать | CVE-2019-25098Эксплойта нет | soerennb eXtplorer Archive archive.php path traversalextplorer · extplorer · CWE-22 | Критическая9,8 | — | 1,0 % | 5 янв. 2023 г. |
36Наблюдать | CVE-2023-27842Proof of concept | Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code viaextplorer · extplorer · CWE-277 | Высокая8,8 | — | 2,4 % | 21 мар. 2023 г. |
35Наблюдать | CVE-2023-29657Эксплойта нет | eXtplorer 2.1.15 is vulnerable to Insecure Permissions.extplorer · extplorer · CWE-434 | Высокая8,8 | — | 1,1 % | 12 мая 2023 г. |
34Наблюдать | CVE-2016-4313Proof of concept | Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a ..extplorer · extplorer · CWE-22 | Высокая7,8 | — | 8,7 % | 24 апр. 2017 г. |
28Наблюдать | CVE-2017-12756Эксплойта нет | Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.extplorer · extplorer · CWE-77 | Высокая7,2 | — | 1,2 % | 9 авг. 2017 г. |
27Наблюдать | CVE-2015-5660Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary extplorer · extplorer · CWE-352 | Средняя6,8 | — | 1,0 % | 15 окт. 2015 г. |
27Наблюдать | CVE-2012-3362Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of admextplorer · extplorer · CWE-352 | Средняя6,8 | — | 0,9 % | 12 июл. 2012 г. |
25Наблюдать | CVE-2008-4764Proof of concept | Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read aextplorer · com extplorer · CWE-22 | Средняя5,0 | — | 16,5 % | 27 окт. 2008 г. |
24Наблюдать | CVE-2019-25096Эксплойта нет | soerennb eXtplorer cross site scriptingextplorer · extplorer · CWE-79 | Средняя6,1 | — | 0,6 % | 5 янв. 2023 г. |
24Наблюдать | CVE-2023-40628Эксплойта нет | Extension - Extplorer.net - Reflected XSS in Extplorer component for Joomla 1.0.0-2.1.15extplorer · extplorer · CWE-79 | Средняя6,1 | — | 0,4 % | 14 дек. 2023 г. |
20Наблюдать | CVE-2025-13058Эксплойта нет | soerennb eXtplorer Filename cross site scriptingextplorer · extplorer · CWE-79 | Средняя5,1 | — | 0,3 % | 12 нояб. 2025 г. |
17Наблюдать | CVE-2015-0896Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML extplorer · extplorer · CWE-79 | Средняя4,3 | — | 1,2 % | 18 мар. 2015 г. |
14Наблюдать | CVE-2012-3454Эксплойта нет | eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrextplorer · extplorer · CWE-264 | Низкая3,6 | — | 0,3 % | 7 авг. 2012 г. |
11Наблюдать | CVE-2013-5951Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to injeextplorer · extplorer · CWE-79 | Низкая2,6 | — | 1,9 % | 25 мар. 2014 г. |
- CVE-2012-671046В плане
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an actio
КритическаяCVSS 9,8Готовый эксплойтEPSS 25 %extplorer · extplorer7 окт. 2018 г.
- CVE-2019-730540В плане
eXtplorer exposes /usr and /etc/extplorer over HTTP
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %extplorer · extplorer9 апр. 2020 г.
- CVE-2023-5433539Наблюдать
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %extplorer · extplorer13 янв. 2026 г.
- CVE-2019-2509739Наблюдать
soerennb eXtplorer Directory Content path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %extplorer · extplorer5 янв. 2023 г.
- CVE-2019-2509839Наблюдать
soerennb eXtplorer Archive archive.php path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %extplorer · extplorer5 янв. 2023 г.
- CVE-2023-2784236Наблюдать
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %extplorer · extplorer21 мар. 2023 г.
- CVE-2023-2965735Наблюдать
eXtplorer 2.1.15 is vulnerable to Insecure Permissions.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %extplorer · extplorer12 мая 2023 г.
- CVE-2016-431334Наблюдать
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a ..
ВысокаяCVSS 7,8Proof of conceptEPSS 9 %extplorer · extplorer24 апр. 2017 г.
- CVE-2017-1275628Наблюдать
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %extplorer · extplorer9 авг. 2017 г.
- CVE-2015-566027Наблюдать
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary
СредняяCVSS 6,8Эксплойта нетEPSS 1 %extplorer · extplorer15 окт. 2015 г.
- CVE-2012-336227Наблюдать
Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of adm
СредняяCVSS 6,8Эксплойта нетEPSS 1 %extplorer · extplorer12 июл. 2012 г.
- CVE-2008-476425Наблюдать
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read a
СредняяCVSS 5,0Proof of conceptEPSS 17 %extplorer · com extplorer27 окт. 2008 г.
- CVE-2019-2509624Наблюдать
soerennb eXtplorer cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %extplorer · extplorer5 янв. 2023 г.
- CVE-2023-4062824Наблюдать
Extension - Extplorer.net - Reflected XSS in Extplorer component for Joomla 1.0.0-2.1.15
СредняяCVSS 6,1Эксплойта нетEPSS 0 %extplorer · extplorer14 дек. 2023 г.
- CVE-2025-1305820Наблюдать
soerennb eXtplorer Filename cross site scripting
СредняяCVSS 5,1Эксплойта нетEPSS 0 %extplorer · extplorer12 нояб. 2025 г.
- CVE-2015-089617Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Эксплойта нетEPSS 1 %extplorer · extplorer18 мар. 2015 г.
- CVE-2012-345414Наблюдать
eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwr
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %extplorer · extplorer7 авг. 2012 г.
- CVE-2013-595111Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inje
НизкаяCVSS 2,6Эксплойта нетEPSS 2 %extplorer · extplorer25 мар. 2014 г.