CVE-2010-10013 CRITICAL

CVE-2010-10013: AjaXplorer < 2.6 checkInstall.php Unauthenticated RCE

Vendor Ajaxplorer
Product AjaXplorer
Weakness CWE-78
Published August 8, 2025
Last update May 15, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell metacharacters, remote attackers can execute arbitrary system commands on the server with the privileges of the web server process.

Key dates

02Disclosure timeline

August 8, 2025 CVE published
May 15, 2026 Record updated