CVE-2013-4267: OS Command Injection
Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archivename parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the File System (Standard) module (plugins/access.fs/class.fsAccessWrapper.php), or the (3) revision parameter to the Subversion Repository module (plugins/meta.svn/class.SvnManager.php).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4267?
The severity of CVE-2013-4267 is critical with a severity value of 9.8.
How does CVE-2013-4267 allow attackers to execute arbitrary commands?
CVE-2013-4267 allows remote attackers to execute arbitrary commands by using shell metacharacters in certain parameters.
Which version of Ajaxeplorer is affected by CVE-2013-4267?
Ajaxeplorer versions before 5.0.1 are affected by CVE-2013-4267.
Is there a fix available for CVE-2013-4267?
Yes, there is a fix available for CVE-2013-4267. Upgrading to version 5.0.1 or later of Ajaxeplorer will address the vulnerability.
Where can I find more information about CVE-2013-4267?
You can find more information about CVE-2013-4267 at the following references: [reference links]