vendor:
QuiXplorer
by:
PCA & krhr_krhr
7.5
CVSS
HIGH
File Upload Vulnerability
CWE
Product Name: QuiXplorer
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux, Windows
2011
QuiXplorer 2.3 <= Bugtraq File Upload Vulnerability
QuiXplorer 2.3 allows remote attackers to upload arbitrary files via the index.php?action=upload&order=name&srt=yes parameter.
Mitigation:
Update to a patched version of QuiXplorer.