CVE-2019-7305: eXtplorer exposes /usr and /etc/extplorer over HTTP
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7305?
CVE-2019-7305 has a medium severity level due to the potential for information exposure.
How do I fix CVE-2019-7305?
To fix CVE-2019-7305, ensure that the system directories /usr/ and /etc/extplorer/ are properly restricted to prevent world access.
What systems are affected by CVE-2019-7305?
CVE-2019-7305 primarily affects eXtplorer versions up to and including 2.1.0.
What can happen if CVE-2019-7305 is exploited?
Exploitation of CVE-2019-7305 can lead to unauthorized access to sensitive system directories, resulting in data leakage.
Is there a patch available for CVE-2019-7305?
Yes, applying the latest updates of eXtplorer will include fixes for CVE-2019-7305.