Vulnerability Bulletins

DSA-2882 extplorer - security update


System information

   
Affected software Debian

Description

Multiple cross-site scripting (XSS) vulnerabilities have been discoveredin extplorer, a web file explorer and manager using Ext JS.A remote attacker can inject arbitrary web script or HTML code via acrafted string in the URL to application.js.php, admin.php, copy_move.php,functions.php, header.php and upload.php.

More info:

http://www.debian.org/security/2014/dsa-2882

Standar resources

Property Value
CVE CVE-2013-5951 and DSA-2882.

Version history

Version Comments Date
1.0 Advisory issued 2014-03-23
Ministerio de Defensa
CNI
CCN
CCN-CERT