AjaXplorer Remote Command Injection and Local File Disclosure Vulnerabilities
BID:39334
Info
AjaXplorer Remote Command Injection and Local File Disclosure Vulnerabilities
| Bugtraq ID: | 39334 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2010 12:00AM |
| Updated: | Oct 04 2013 12:13AM |
| Credit: | Julien Cayssol |
| Vulnerable: |
AjaXplorer AjaXplorer 2.5.5 AjaXplorer AjaXplorer 2.5.3 AjaXplorer AjaXplorer 2.5.2 |
| Not Vulnerable: |
AjaXplorer AjaXplorer 2.6.1 AjaXplorer AjaXplorer 2.6 |
Discussion
AjaXplorer Remote Command Injection and Local File Disclosure Vulnerabilities
AjaXplorer is prone to a remote command injection vulnerability and a local file disclosure vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary commands within the context of the affected application and to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Versions prior to AjaXplorer 2.6 are vulnerable.
AjaXplorer is prone to a remote command injection vulnerability and a local file disclosure vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary commands within the context of the affected application and to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Versions prior to AjaXplorer 2.6 are vulnerable.
Exploit / POC
AjaXplorer Remote Command Injection and Local File Disclosure Vulnerabilities
An attacker can exploit these issues via a browser.
The following exploit code is available:
An attacker can exploit these issues via a browser.
The following exploit code is available:
Solution / Fix
AjaXplorer Remote Command Injection and Local File Disclosure Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
AjaXplorer AjaXplorer 2.5.5
Solution:
Updates are available. Please see the references for more information.
AjaXplorer AjaXplorer 2.5.5
-
AjaXplorer AjaXplorer 2.6
http://sourceforge.net/projects/ajaxplorer/files/ajaxplorer/2.6/ajaxpl orer-core-2.6.zip/download
References
AjaXplorer Remote Command Injection and Local File Disclosure Vulnerabilities
References:
References:
- AjaXplorer 2.6 (security) �?? AjaXplorer 2.7.1 (3.0 early-�?) (AjaXplorer)
- AjaXplorer Homepage (AjaXplorer)