← Back

Webfileexplorer

webfileexplorer

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webfileexplorer
1Web File Explorer
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.
1Webfileexplorer
1Web File Explorer
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Webfileexplorer
1Web File Explorer
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.