CVE-2012-1840: Ajaxplorer
High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.
AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login access by leveraging knowledge of a password hash.
Affected products
- Ajaxplorer Ajaxplorer: version 3.2 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 4.0 only; …
Published 2012-03-22. Last modified 2026-06-16.