CVE-2019-7305

Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian
References
Link Resource
https://launchpad.net/bugs/1822013 Issue Tracking Third Party Advisory
https://launchpad.net/bugs/1822013 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:extplorer:extplorer:*:*:*:*:*:*:*:*
OR cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:47

Type Values Removed Values Added
References () https://launchpad.net/bugs/1822013 - Issue Tracking, Third Party Advisory () https://launchpad.net/bugs/1822013 - Issue Tracking, Third Party Advisory
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 5.8

Information

Published : 2020-04-10 00:15

Updated : 2024-11-21 04:47


NVD link : CVE-2019-7305

Mitre link : CVE-2019-7305

CVE.ORG link : CVE-2019-7305


JSON object : View

Products Affected

extplorer

  • extplorer

canonical

  • ubuntu_linux

debian

  • debian_linux
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-552

Files or Directories Accessible to External Parties