← Back

Dext5

dext5

6 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Dext5
dext5
Dext5upload
dext5upload
Dext5 Editor
dext5_editor

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dext5
1Dext5upload
Jun 17, 2026
Oct 28, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged fo...Show more
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.Show less
1Dext5
1Dext5
Jun 17, 2026
Sep 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile function.(CVE-2020-7832)
1Dext5
1Dext5 Editor
Jun 17, 2026
Jun 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz DEXT5Editor versions prior to 3.5.1405747.1100.03.
1Dext5
1Dext5upload
Jun 17, 2026
Dec 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPa...Show more
DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct fileOrgName value).Show less
1Dext5
1Dext5
Jun 17, 2026
Jun 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
1Dext5
1Dext5
Jun 17, 2026
May 25, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.