CVE-2017-12756: Command Injection
Published Aug 9, 2017
·Updated
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.
Affected Software
1 affected component
eXtplorer extplorer<=2.1.9
Event History
Aug 9, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12756?
CVE-2017-12756 is rated as high severity due to its potential for command injection attacks.
2
How do I mitigate CVE-2017-12756?
To mitigate CVE-2017-12756, upgrade extplorer to version 2.1.10 or later, which addresses the vulnerability.
3
What are the potential impacts of CVE-2017-12756?
The potential impacts of CVE-2017-12756 include unauthorized command execution on the server, leading to data breaches and service disruptions.
4
Is my system vulnerable to CVE-2017-12756?
If you are using extplorer version 2.1.9 or earlier, your system is vulnerable to CVE-2017-12756.
5
What type of attacks can occur due to CVE-2017-12756?
CVE-2017-12756 allows attackers to perform command injection, which can lead to system compromise and execution of arbitrary commands.