← Back

Dext5

dext5

6 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Dext5
dext5
Dext5upload
dext5upload
Dext5 Editor
dext5_editor

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dext5
1Dext5upload
Nov 21, 2024
Oct 28, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged fo...Show more
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.Show less
1Dext5
1Dext5
Nov 21, 2024
Sep 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile function.(CVE-2020-7832)
1Dext5
1Dext5 Editor
Nov 21, 2024
Jun 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz DEXT5Editor versions prior to 3.5.1405747.1100.03.
1Dext5
1Dext5upload
Nov 21, 2024
Dec 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPa...Show more
DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct fileOrgName value).Show less
1Dext5
1Dext5
Nov 21, 2024
Jun 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
1Dext5
1Dext5
Nov 21, 2024
May 25, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.