CVE-2011-5005: Claudio Klingler Quixplorer

High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.

Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension using the upload action to index.php, then accessing it via a direct request to the file in an unspecified directory.

Affected products

  • Claudio Klingler Quixplorer: up to and including 2.3; version 1.0 only; version 1.1 only; version 1.2 only; version 1.4 only; version 1.5 only; …
  • Mads Brunn t3quixplorer: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.2.0 only; version 1.3.0 only; version 1.4.0 only; …

Published 2011-12-25. Last modified 2026-06-16.