« Volver al listado

CVE-2013-5688

Estado: ModificadaMedia (5.5)—💥 Exploit

Múltiples vulnerabilidades de salto de directorio en index.php en AjaXplorer 5.0.2 y anteriores permite a usuarios remotos autenticados leer arbitrarios a través de .. / 00% (punto punto barra invertida byte nulo) en el parámetro de archivo de una descarga (1) ,una acción get_content (2), o (3) subir archivos arbitrarios a través de .. / 00% (punto punto barra inversa codificada byte nulo) en el parámetro dir en una acción de subida de ficheros.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-5688",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-11-05T21:55:12.187",
  "references": [
    {
      "url": "http://ajaxplorer.info/ajaxplorer-core-5-0-3/",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/97022",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.trustwave.com/spiderlabs/advisories/TWSL2013-027.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ajaxplorer.info/ajaxplorer-core-5-0-3/",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/97022",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.trustwave.com/spiderlabs/advisories/TWSL2013-027.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the dir parameter in an upload action."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de salto de directorio en index.php en AjaXplorer 5.0.2 y anteriores permite a usuarios remotos autenticados leer arbitrarios  a través de .. / 00% (punto punto barra invertida  byte nulo) en el parámetro de archivo de una  descarga (1) ,una acción get_content (2), o (3) subir archivos arbitrarios a través de .. / 00% (punto punto barra inversa codificada byte nulo) en el parámetro dir en una acción de subida de ficheros."
    }
  ],
  "lastModified": "2026-06-16T23:59:14.693",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C58198A4-09F0-488E-AB59-30AF073DC7F7",
              "versionEndIncluding": "5.0.2"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C9B8E9F-8B96-4772-A85B-EA9627A936C5"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D05FAAAF-FFE2-43FC-8540-9A6FD442FEA3"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BC21F4F-F8DB-4C93-A50E-3368BAD1D25E"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25D9757C-A57E-4055-ACFE-A05AA7974BBD"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCDAE4D9-9B4F-4DBE-A6D9-FCF834385786"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1143B0E5-E295-4FB2-97C3-9050D4657B54"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA105880-BD2F-49F7-A075-DE82A1CD2AE2"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DF81994-870E-4B13-BD4C-075AD817D482"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:2.7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5BD079C-588C-4871-9DAD-D6B5D9F8DD77"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5714ADF6-AE3D-4673-80A4-B0B85D4F28D4"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F41BF0E-36A9-4112-B684-C230B34E9089"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6716313-262B-4CAA-9CBB-16058310F57E"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E59657D9-1B5E-4424-BA56-47B20060E090"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D6EA2C3-05B5-4553-88C8-8D4525365037"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89DE9891-BAAB-4013-88BD-A74ED1F4CB9C"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AB14FF4-0CF0-4ACF-BA85-59196A259BAA"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA399184-3366-48E8-90F8-0BDF255DB2CA"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD6997D4-21C7-459F-8CB1-31E98C44BC91"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08354E81-1FF5-4CEF-8B5B-A3B3C514F03B"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC4FFE75-9BBE-4C9F-A7E5-350AC7701ECD"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "642C57C5-9442-4497-827D-3DADBC427080"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FE8026C-D902-4009-9DBF-8DF74A755727"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4230D03A-9192-42DD-9EDB-CED5CC974CDD"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5CC29EA-42E9-465C-B1D0-A9262BAB997E"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3DDE2900-5D3F-4389-8B2F-64A8D0E132B1"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "514ED912-D7FB-46CD-999C-4099D37DBF21"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9ACB6977-00FC-49D4-ACAA-E5BDF51E2533"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF45470B-525A-4716-B3C7-E75A33E89466"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0ABE4444-20F2-43D8-83BC-12839AA40AF3"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50C4C675-E933-4282-8301-FB39B9222F68"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0BA12F9-9F0A-4BA7-8697-710AC4959149"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0FF8CD1-0EA4-4A6F-95DD-2DDB9844A3C9"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F205E235-1831-41FB-8055-18FDB95204CE"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:5.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8866C26C-EF22-41AA-9826-5D7F9382DA02"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E6B0759-661B-4217-9918-23AFED8213E9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}