cbcvebase.

Roxyfileman Roxy Fileman vulnerabilities

6 known vulnerabilities affecting roxyfileman/roxy_fileman.

Total CVEs
6
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH2

Vulnerabilities

Page 1 of 1
CVE-2018-20526P1CRITICALCVSS 9.8ExploitedPoCv1.4.52019-03-21
CVE-2018-20526 [CRITICAL] CWE-434 CVE-2018-20526: Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
nvd
CVE-2018-20525P2CRITICALCVSS 9.1PoCv1.4.52019-03-21
CVE-2018-20525 [CRITICAL] CWE-22 CVE-2018-20525: Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
nvd
CVE-2019-19731P2HIGHCVSS 7.5PoCv1.4.52019-12-16
CVE-2019-19731 [HIGH] CWE-22 CVE-2019-19731: Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded fi Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Wi
nvd
CVE-2022-40797P2CRITICALCVSS 9.8v1.4.62022-11-09
CVE-2022-40797 [CRITICAL] CWE-434 CVE-2022-40797: Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UP Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)
nvd
CVE-2019-7174P3CRITICALCVSS 9.8v1.4.52019-04-09
CVE-2019-7174 [CRITICAL] CVE-2019-7174: Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations.
nvd
CVE-2018-12042P3HIGHCVSS 7.5≤ 1.4.52018-06-07
CVE-2018-12042 [HIGH] CWE-22 CVE-2018-12042: Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter. Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.
nvd
Roxyfileman Roxy Fileman vulnerabilities | cvebase