eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Extplorer |
Extplorer |
2.1.0-b6 (including) |
2.1.0-b6 (including) |
References