Description
Ext JS is a pure JavaScript application framework for building interactive web applications using techniques such as Ajax, DHTML and DOM scripting. Baidu Security Team found a vulnerability in the examples provided with Ext JS that allows an attacker to initiate arbitrary HTTP requests and (in some conditions) read arbitrary files from the server.
Remediation
Restrict access to the examples directory provided with Ext JS.
References
Related Vulnerabilities
WordPress Plugin BP Group Documents Multiple Vulnerabilities (1.2.1)
WordPress Plugin All-in-One Video Gallery Local File Inclusion (2.4.9)
ExpressJs Local File Read via the layout parameter
WordPress Plugin SEO Tools 'file' Parameter Directory Traversal (3.1.7)
WordPress Plugin S3Bubble Cloud Video With Adverts & Analytics Arbitrary File Download (0.7)