An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell metacharacters, remote attackers can execute arbitrary system commands on the server with the privileges of the web server process.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ajaxplorer
Ajaxplorer ajaxplorer |
|
Vendors & Products |
Ajaxplorer
Ajaxplorer ajaxplorer |
Fri, 08 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 08 Aug 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell metacharacters, remote attackers can execute arbitrary system commands on the server with the privileges of the web server process. | |
Title | AjaXplorer < 2.6 checkInstall.php Unauthenticated RCE | |
Weaknesses | CWE-78 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-08T18:09:40.513Z
Updated: 2025-08-08T19:01:16.689Z
Reserved: 2025-08-07T16:27:21.673Z
Link: CVE-2010-10013

Updated: 2025-08-08T19:01:06.605Z

Status : Awaiting Analysis
Published: 2025-08-08T19:15:32.710
Modified: 2025-08-08T20:30:18.180
Link: CVE-2010-10013

No data.