CVE-2017-12756: Extplorer

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.

Affected products

  • Extplorer Extplorer: up to and including 2.1.9

Published 2017-08-09. Last modified 2026-06-17.