Vulnerabilities
Vulnerable Software
Tecrail:  >> Responsive Filemanager  Security Vulnerabilities
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.
CVSS Score
7.5
EPSS Score
0.019
Published
2019-02-25
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.
CVSS Score
7.5
EPSS Score
0.008
Published
2019-02-25
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.
CVSS Score
7.5
EPSS Score
0.013
Published
2019-02-25
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.
CVSS Score
8.6
EPSS Score
0.004
Published
2018-10-31
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files.
CVSS Score
7.5
EPSS Score
0.002
Published
2018-10-10
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-10-10
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.
CVSS Score
7.5
EPSS Score
0.805
Published
2018-08-24
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.
CVSS Score
5.5
EPSS Score
0.066
Published
2018-08-24
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.
CVSS Score
7.5
EPSS Score
0.004
Published
2018-08-18
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
CVSS Score
9.8
EPSS Score
0.929
Published
2018-08-03


Contact Us

Shodan ® - All rights reserved