CVE-2011-5005
Published Dec 25, 2011
Last updated 7 years ago
Overview
- Description
- Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension using the upload action to index.php, then accessing it via a direct request to the file in an unspecified directory.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13FBDE35-7E96-4CB0-AA02-20A54E25C034", "versionEndIncluding": "2.3" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "354BBE12-96AA-4F3C-8B51-CFE80E4808D6" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9FCFC487-FDA2-4D26-8140-1F16BAA7A658" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B19E0034-0B67-4A71-83E8-98A148FF89F4" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F06FAD64-5233-44BB-9FDA-ED019967B7D0" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9541428-5609-43FE-BF9B-49414E64D0B7" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AE410E3-E0AB-4C47-AB4A-7290460BB9BD" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF42BE37-1569-4D22-9302-B1F5AB12C0B8" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DFF152CB-58C1-4B9A-87E0-16A7E9EFF7EE" }, { "criteria": "cpe:2.3:a:claudio_klingler:quixplorer:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83892CE6-D168-4B03-94C8-CE167326FA60" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.0.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE727C14-8517-4996-8D34-FAF238CB3429" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03A9826B-068A-4923-B3C7-02EA3C732038" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C03C88C-5D51-4720-90C8-EDFF288702AA" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8B77C9D-C67F-4D46-928F-50811DEF43F4" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA0BD9C3-199A-4C23-B9E2-FC30C8461B0E" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D26478C-CF65-43D7-81F9-A2EB14F94689" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3B9A49E-17E4-4118-8AB4-B42259123E4E" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A423F65-9148-4393-BB29-0BCB72557C83" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13CB2420-FEDA-41E7-B650-84C71BFC0EAA" }, { "criteria": "cpe:2.3:a:mads_brunn:t3quixplorer:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8995BEFE-4E47-47ED-88DA-3BA06D4B2392" } ], "operator": "OR" } ] } ]