Description
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.
Problem types
Missing Authentication for Critical Function
Product status
Credits
ErPaciocco
References
www.exploit-db.com/exploits/51067
www.exploit-db.com/exploits/51067 (ExploitDB-51067)
extplorer.net/ (Official eXtplorer Product Homepage)
www.vulncheck.com/...cation-bypass-remote-code-execution-rce (VulnCheck Advisory: eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE))