AjaXplorer is prone to a remote command injection vulnerability and a local file disclosure vulnerability because it fails to adequately sanitize user-supplied input data. Attackers can exploit this issue to execute arbitrary commands within the context of the affected application and to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks. Versions prior to AjaXplorer 2.6 are vulnerable.
Updates are available. Please see the references for more information.
- Apache Struts2 'XWork' Information Disclosure Vulnerability
- Apache Web Server ETag Header Information Disclosure Weakness
- Apache Struts2/XWork Remote Command Execution Vulnerability
- AdaptCMS Lite Cross Site Scripting and Remote File Include Vulnerabilities
- Apache Tomcat source.jsp malformed request information disclosure