Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
CVE-2017-12756 Fix command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the . Hash: SHA512 Package : extplorer Version : 2.1.0b6+dfsg.3-4+deb7u5 CVE ID : CVE-2017-12756 CVE-2017-12756 Fix command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter. For Debian 7 "Wheezy", these problems have been fixed in version 2.1.0b6+dfsg.3-4+deb7u5. We recommend that you upgrade your extplorer packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Critical security patch released for Debian 7 targeting remote code execution vulnerability, users advised to upgrade software immediately.. Extplorer Security Update, Debian LTS Update, Command Injection Resolution, Extplorer Vulnerability Fix. . Severity: Critical. LinuxSecurity.com Team
Multiple cross-site scripting (XSS) vulnerabilities have been discovered in extplorer, a web file explorer and manager using Ext JS. A remote attackers can inject arbitrary web script or HTML code via a crafted string in the URL to application.js.php, admin.php, copy_move.php, . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2882-1
John Leitch has discovered a vulnerability in eXtplorer, a very feature rich web server file manager, which can be exploited by malicious people to conduct cross-site request forgery attacks. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2510-1
Get the latest Linux and open source security news straight to your inbox.