Refine your search

3 vulnerabilities found for eXtplorer by Extplorer

CVE-2023-54335 (GCVE-0-2023-54335)
Vulnerability from cvelistv5
Published
2026-01-13 22:52
Modified
2026-04-07 14:08
CWE
  • CWE-306 - Missing Authentication for Critical Function
Summary
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.
Impacted products
Vendor Product Version
Extplorer eXtplorer Version: 0    2.1.14
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-54335",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-01-14T15:46:35.392834Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-01-14T19:18:10.942Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://www.exploit-db.com/exploits/51067"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "eXtplorer",
          "vendor": "Extplorer",
          "versions": [
            {
              "lessThanOrEqual": "2.1.14",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:extplorer:extplorer:*:*:*:*:*:joomla\\!:*:*",
                  "versionEndIncluding": "2.1.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "ErPaciocco"
        }
      ],
      "datePublic": "2023-03-27T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-306",
              "description": "Missing Authentication for Critical Function",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-07T14:08:22.364Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "ExploitDB-51067",
          "tags": [
            "exploit"
          ],
          "url": "https://www.exploit-db.com/exploits/51067"
        },
        {
          "name": "Official eXtplorer Product Homepage",
          "tags": [
            "product"
          ],
          "url": "https://extplorer.net/"
        },
        {
          "name": "VulnCheck Advisory: eXtplorer\u003c= 2.1.14 - Authentication Bypass \u0026 Remote Code Execution (RCE)",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/extplorer-authentication-bypass-remote-code-execution-rce"
        }
      ],
      "title": "eXtplorer\u003c= 2.1.14 - Authentication Bypass \u0026 Remote Code Execution (RCE)",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2023-54335",
    "datePublished": "2026-01-13T22:52:08.000Z",
    "dateReserved": "2026-01-10T01:51:52.983Z",
    "dateUpdated": "2026-04-07T14:08:22.364Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

jvndb-2015-000126
Vulnerability from jvndb
Published
2015-10-15 12:24
Modified
2015-10-19 15:55
Severity ?
() - -
Summary
eXtplorer vulnerable to cross-site request forgery
Details
eXtplorer is a web-based file manager. index.php of eXtplorer contains a cross-site request forgery (CWE-352) vulnerability. Gen Sato of TRADE WORKS Co.,Ltd. Security Dept. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Impacted products
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000126.html",
  "dc:date": "2015-10-19T15:55+09:00",
  "dcterms:issued": "2015-10-15T12:24+09:00",
  "dcterms:modified": "2015-10-19T15:55+09:00",
  "description": "eXtplorer is a web-based file manager. index.php of eXtplorer contains a cross-site request forgery (CWE-352) vulnerability.\r\n\r\nGen Sato of TRADE WORKS Co.,Ltd. Security Dept. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
  "link": "https://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000126.html",
  "sec:cpe": {
    "#text": "cpe:/a:extplorer:extplorer",
    "@product": "eXtplorer",
    "@vendor": "eXtplorer",
    "@version": "2.2"
  },
  "sec:cvss": {
    "@score": "5.1",
    "@severity": "Medium",
    "@type": "Base",
    "@vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
    "@version": "2.0"
  },
  "sec:identifier": "JVNDB-2015-000126",
  "sec:references": [
    {
      "#text": "http://jvn.jp/en/jp/JVN92520335/index.html",
      "@id": "JVN#92520335",
      "@source": "JVN"
    },
    {
      "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5660",
      "@id": "CVE-2015-5660",
      "@source": "CVE"
    },
    {
      "#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5660",
      "@id": "CVE-2015-5660",
      "@source": "NVD"
    },
    {
      "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
      "@id": "CWE-352",
      "@title": "Cross-Site Request Forgery(CWE-352)"
    }
  ],
  "title": "eXtplorer vulnerable to cross-site request forgery"
}

jvndb-2015-000039
Vulnerability from jvndb
Published
2015-03-17 13:41
Modified
2015-03-20 14:30
Severity ?
() - -
Summary
eXtplorer vulnerable to cross-site scripting
Details
eXtplorer is a web-based file manager. eXtplorer contains multiple cross-site scripting vulnerabilities. Yuji Tounai of NTT COM Security reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Impacted products
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000039.html",
  "dc:date": "2015-03-20T14:30+09:00",
  "dcterms:issued": "2015-03-17T13:41+09:00",
  "dcterms:modified": "2015-03-20T14:30+09:00",
  "description": "eXtplorer is a web-based file manager. eXtplorer contains multiple cross-site scripting vulnerabilities.\r\n\r\nYuji Tounai of NTT COM Security reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
  "link": "https://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000039.html",
  "sec:cpe": {
    "#text": "cpe:/a:extplorer:extplorer",
    "@product": "eXtplorer",
    "@vendor": "eXtplorer",
    "@version": "2.2"
  },
  "sec:cvss": {
    "@score": "4.3",
    "@severity": "Medium",
    "@type": "Base",
    "@vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
    "@version": "2.0"
  },
  "sec:identifier": "JVNDB-2015-000039",
  "sec:references": [
    {
      "#text": "http://jvn.jp/en/jp/JVN97099798/index.html",
      "@id": "JVN#97099798",
      "@source": "JVN"
    },
    {
      "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0896",
      "@id": "CVE-2015-0896",
      "@source": "CVE"
    },
    {
      "#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0896",
      "@id": "CVE-2015-0896",
      "@source": "NVD"
    },
    {
      "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
      "@id": "CWE-79",
      "@title": "Cross-site Scripting(CWE-79)"
    }
  ],
  "title": "eXtplorer vulnerable to cross-site scripting"
}