Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-19731

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.254
EPSS Ranking 96.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-19731


Contact Us

Shodan ® - All rights reserved