CVE Tools

Description

Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent.

In plain language

AI Worth attention

CVE-2007-2285 is a bug in an old Ext JS add-on (Jack Slocum Ext 1.0 alpha1) that can let an internet attacker read files on your server, without needing a login; if you still run this add-on, you should act.

Executive summary

Directory traversal in Jack Slocum Ext 1.0 alpha1 (Ext JS) via feed-proxy.php allows remote, unauthenticated attackers to read arbitrary server files by using .. in the feed parameter.

If affected, business impact
Sensitive files exposedCredentials and documents leakagePrivacy breach riskReputation and compliance risk

What to do now

  1. Check whether your application uses Jack Slocum Ext 1.0 alpha1 (Ext JS) and includes the script examples/layout/feed-proxy.php.
  2. If you use it, remove/disable this component and replace it with a non-vulnerable alternative (a fixed version is not known for this CVE).
  3. Confirm whether the affected endpoint is reachable from the internet; if it is, treat it as exposed until removed/blocked.
  4. If you cannot remove it immediately, add strict input validation at the feed parameter and block direct access to feed-proxy.php (temporary containment) while you plan a replacement.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LAu:NC:CI:NA:N
Exploitability
AV:NAccess Vector
Network
AC:LAccess Complexity
Low
Au:NAuthentication
None
Impact
C:CConfidentiality
Complete
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

References

and 4 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2007-2285 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store