CVE-2019-7305

Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian
References
Link Resource
https://launchpad.net/bugs/1822013 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:extplorer:extplorer:*:*:*:*:*:*:*:*
OR cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:-:*:*:*:*:*:*:*

History

13 Sep 2021, 14:24

Type Values Removed Values Added
CPE cpe:2.3:a:extplorer:extplorer:-:*:*:*:*:*:*:* cpe:2.3:a:extplorer:extplorer:*:*:*:*:*:*:*:*
CWE CWE-200 CWE-552

Information

Published : 2020-04-10 00:15

Updated : 2023-12-10 13:27


NVD link : CVE-2019-7305

Mitre link : CVE-2019-7305

CVE.ORG link : CVE-2019-7305


JSON object : View

Products Affected

debian

  • debian_linux

canonical

  • ubuntu_linux

extplorer

  • extplorer
CWE
CWE-552

Files or Directories Accessible to External Parties

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor