CVE-2022-44276
- EPSS 25.4%
- Veröffentlicht 28.06.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:27:49
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
CVE-2022-46604
- EPSS 36.43%
- Veröffentlicht 02.02.2023 13:15:09
- Zuletzt bearbeitet 27.03.2025 14:15:19
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.
CVE-2017-20145
- EPSS 0.5%
- Veröffentlicht 25.07.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 03:22:44
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading...
CVE-2020-11106
- EPSS 0.47%
- Veröffentlicht 30.03.2020 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:56:48
An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the...
CVE-2020-10567
- EPSS 17.87%
- Veröffentlicht 14.03.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:35
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legit...
CVE-2020-10212
- EPSS 0.98%
- Veröffentlicht 07.03.2020 00:15:13
- Zuletzt bearbeitet 21.11.2024 04:54:58
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt ma...
CVE-2018-20792
- EPSS 0.94%
- Veröffentlicht 25.02.2019 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:11
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php.
CVE-2018-20795
- EPSS 0.94%
- Veröffentlicht 25.02.2019 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:11
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.
CVE-2018-20794
- EPSS 0.61%
- Veröffentlicht 25.02.2019 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:11
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.
CVE-2018-20793
- EPSS 1.38%
- Veröffentlicht 25.02.2019 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:11
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.