AjaXplorer < 2.6 checkInstall.php Unauthenticated RCE
Vulnerability Description
An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell metacharacters, remote attackers can execute arbitrary system commands on the server with the privileges of the web server process.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-10013
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Julien Cayssol
References
- https://sourceforge.net/projects/ajaxplorer/
- https://www.exploit-db.com/exploits/21993
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/ajaxplorer_checkinstall_exec.rb
- https://www.tenable.com/plugins/nessus/45489
- https://www.vulncheck.com/advisories/ajaxplorer-unauth-rce
Affected Vendor
AjaXplorer
View all reports →