Description
Ext JS is a pure JavaScript application framework for building interactive web applications using techniques such as Ajax, DHTML and DOM scripting. Baidu Security Team found a vulnerability in the examples provided with Ext JS that allows an attacker to initiate arbitrary HTTP requests and (in some conditions) read arbitrary files from the server.
Remediation
Restrict access to the examples directory provided with Ext JS.
References
Related Vulnerabilities
WordPress Plugin WP Post Popup Directory Traversal (2.1.1)
WordPress Plugin Aspose Cloud eBook Generator Arbitrary File Download (1.0)
WordPress Plugin Spicy Blogroll Local File Include (1.0.0)
WordPress Plugin Booking Calendar Directory Traversal (7.0)
WordPress Plugin Payment Gateways Caller for WP e-Commerce Local File Inclusion (0.1)