CVE-2013-5688: Ajaxplorer

Medium severity, CVSS 5.5. EPSS: 6.2% chance of exploitation in the next 30 days.

Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the dir parameter in an upload action.

Affected products

  • Ajaxplorer Ajaxplorer: up to and including 5.0.2; version 2.3.3 only; version 2.3.4 only; version 2.5 only; version 2.5.4 only; version 2.5.5 only; …

Published 2013-11-05. Last modified 2026-06-16.