CVE-2010-10013 Information
Description
An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell metacharacters remote attackers can execute arbitrary system commands on the server with the privileges of the web server process.
Reference
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/ajaxplorer_checkinstall_exec.rb https://sourceforge.net/projects/ajaxplorer/ https://www.exploit-db.com/exploits/21993 https://www.tenable.com/plugins/nessus/45489 https://www.vulncheck.com/advisories/ajaxplorer-unauth-rce https://www.exploit-db.com/exploits/21993 https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/ajaxplorer_checkinstall_exec.rb
Related CNNVD
CNNVD-202508-771 (Published: 2025-08-08)
Share on: