Arbitrary Command Execution in Ajaxeplorer by Pydio
CVE-2013-4267
9.8CRITICAL
What is CVE-2013-4267?
The Ajaxeplorer application before version 5.0.1 is susceptible to remote command execution flaws due to insufficient validation of user input in multiple parameters. Attackers can exploit these vulnerabilities by injecting shell metacharacters through the archive_name parameter in the Power FS module, manipulating file names in the getTrustSizeOnFileSystem function, or the revision parameter in the Subversion Repository module. These weaknesses could potentially allow attackers to execute arbitrary commands on the server.
Affected Version(s)
Ajaxeplorer before 5.0.1
