Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-27842: eXtplorer - a PHP-based File Manager

Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent

CVE
#vulnerability#web#js#java#php

eXtplorer is a php-based file manager

eXtplorer Features¶

The Main Features of eXtplorer are:

  • Copy & Move Files and Directories by Drag&Drop

  • Dynamic Directory Tree with on-demand loading of subdirectories

  • Edit Files (with Syntax-Highlighting thanks to EditArea)

  • Rename, Delete or Create new Files and Directories

  • Access Files through ‘’FTP’’ or directly (using PHP) to totally overcome permission and file ownership issues

  • Upload or Download files just as you like

  • Create and Extract Archives (ZIP, Tar, Tar/GZ, Tar/BZ)

  • User Management with different permission levels like “View only” or “Edit” and “Admin”

  • Easy Install:

    • As a component for Joomla!.
    • Upload the install file to your web host

All these features are packed into an intuitive Layout which makes working with files very easy. Thanks to the great ExtJS Javascript Library you can drag & drop folders and files, filter directories and sort the file list using various criteria.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907