CVE-2019-7305
Summary
| CVE | CVE-2019-7305 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-10 00:15:00 UTC |
| Updated | 2021-09-13 14:24:00 UTC |
| Description | Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian |
Risk And Classification
Problem Types: CWE-552
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | - | All | All | All |
| Operating System | Canonical | Ubuntu Linux | - | All | All | All |
| Operating System | Debian | Debian Linux | - | All | All | All |
| Operating System | Debian | Debian Linux | - | All | All | All |
| Application | Extplorer | Extplorer | - | All | All | All |
| Application | Extplorer | Extplorer | - | All | All | All |
| Application | Extplorer | Extplorer | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1822013 “extplorer package exposes /usr/ (and /etc/extplore...” : Bugs : extplorer package : Ubuntu | MISC | launchpad.net | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Sander Bos
There are currently no legacy QID mappings associated with this CVE.