AndExplorer vulnerable to directory traversal


AndExplorer provided by LYSESOFT contains an issue in processing file names, which may result in a directory traversal (CWE-22) vulnerability.

Ryohei Koike of Sakura Information Systems Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products

  • AndExplorer versions released prior to April 3, 2014
  • AndExplorer Pro versions released prior to April 5, 2014


A remote, unauthenticated attacker may create an arbitrary file or overwrite an existing file in a directory that the application has privileges to access.

[Update the software]
Update the software if you are using a version of AndExplorer that was downloaded prior to April 3, 2014 or using a version of AndExplorerPro that was downloaded prior to April 5, 2014.

The software version that is downloaded will differ depending on the version of Android OS that you are using.
Vendor Information

CWE (What is CWE?)

  1. Path Traversal(CWE-22) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2014-1974

  1. JVN : JVN#22670349
  2. National Vulnerability Database (NVD) : CVE-2014-1974
Revision History

  • [2014/04/18]
      Web page was published
      References : Content was added