Description
Ext JS is a pure JavaScript application framework for building interactive web applications using techniques such as Ajax, DHTML and DOM scripting. Baidu Security Team found a vulnerability in the examples provided with Ext JS that allows an attacker to initiate arbitrary HTTP requests and (in some conditions) read arbitrary files from the server.
Remediation
Restrict access to the examples directory provided with Ext JS.
References
Related Vulnerabilities
WordPress Plugin WP Source Control Directory Traversal (3.0.0)
WordPress Plugin Autoptimize Multiple Vulnerabilities (2.1.0)
WordPress Plugin Spellchecker 'general.php' Local and Remote File Include Vulnerabilities (3.1)
WordPress Plugin Chat Room Directory Traversal (0.1.2)
WordPress Plugin ZoomSounds-WordPress Wave Audio Player with Playlist Directory Traversal (6.45)