CVE-2013-1641: Quixplorer
High severity, CVSS 7.8. EPSS: 3.7% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the zip download functionality in QuiXplorer before 2.5.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the selitems[] parameter in a download_selected action to index.php.
Affected products
- Quixplorer Quixplorer: up to and including 2.5.4
Published 2014-10-26. Last modified 2026-06-16.