CVE-2007-2285
Description
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent.
In plain language
AI Worth attentionCVE-2007-2285 is a bug in an old Ext JS add-on (Jack Slocum Ext 1.0 alpha1) that can let an internet attacker read files on your server, without needing a login; if you still run this add-on, you should act.
Directory traversal in Jack Slocum Ext 1.0 alpha1 (Ext JS) via feed-proxy.php allows remote, unauthenticated attackers to read arbitrary server files by using .. in the feed parameter.
What to do now
- Check whether your application uses Jack Slocum Ext 1.0 alpha1 (Ext JS) and includes the script examples/layout/feed-proxy.php.
- If you use it, remove/disable this component and replace it with a non-vulnerable alternative (a fixed version is not known for this CVE).
- Confirm whether the affected endpoint is reachable from the internet; if it is, treat it as exposed until removed/blocked.
- If you cannot remove it immediately, add strict input validation at the feed parameter and block direct access to feed-proxy.php (temporary containment) while you plan a replacement.
CVSS Vector Breakdown
AV:NAccess VectorAC:LAccess ComplexityAu:NAuthenticationC:CConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2007-2285 and every CVE in our database. Create a free account — no credit card required.
Create Free Account