CVE-2013-5688

AjaXplorer <= 5.0.2 - Authenticated Path Traversal and Arbitrary File Write via Null Byte in File Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-5688.

AI-analyzed exploit summary The advisory details two vulnerabilities in AjaXplorer: a path traversal (CVE-2013-5688) allowing arbitrary file reads via null-byte injection, and an arbitrary file upload (CVE-2013-5689) enabling remote code execution. It includes HTTP request examples and remediation steps.

Description

Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the dir parameter in an upload action.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/28191

The advisory details two vulnerabilities in AjaXplorer: a path traversal (CVE-2013-5688) allowing arbitrary file reads via null-byte injection, and an arbitrary file upload (CVE-2013-5689) enabling remote code execution. It includes HTTP request examples and remediation steps.

Classification
Writeup 100%
Attack Type
Info Leak | Other
Complexity
Trivial
Reliability
Reliable
Target: AjaXplorer 5.0.2 and prior
Auth required
Prerequisites: Valid secure_token · Access to the application
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/97022

Scores

EPSS 0.0616
EPSS Percentile 92.5%

Details

CWE
CWE-22
Status published
Products (36)
ajaxplorer/ajaxplorer 2.3.3
ajaxplorer/ajaxplorer 2.3.4
ajaxplorer/ajaxplorer 2.5
ajaxplorer/ajaxplorer 2.5.4
ajaxplorer/ajaxplorer 2.5.5
ajaxplorer/ajaxplorer 2.6.0
ajaxplorer/ajaxplorer 2.7.1
ajaxplorer/ajaxplorer 2.7.2
ajaxplorer/ajaxplorer 2.7.3
ajaxplorer/ajaxplorer 3.0
... and 26 more
Published Nov 05, 2013
Tracked Since Feb 18, 2026