Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2021-23407
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path.
0
Attacker Value
Unknown
CVE-2021-23394
Disclosure Date: June 13, 2021 (last updated February 22, 2025)
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
0
Attacker Value
Unknown
CVE-2019-6257
Disclosure Date: January 14, 2019 (last updated November 27, 2024)
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php.
0
Attacker Value
Unknown
CVE-2019-5884
Disclosure Date: January 10, 2019 (last updated November 27, 2024)
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.
0
Attacker Value
Unknown
CVE-2018-9110
Disclosure Date: March 28, 2018 (last updated November 26, 2024)
Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process. NOTE: this issue exists because of an incomplete fix for CVE-2018-9109.
0
Attacker Value
Unknown
CVE-2018-9109
Disclosure Date: March 28, 2018 (last updated November 26, 2024)
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.
0
Attacker Value
Unknown
CVE-2013-1972
Disclosure Date: June 24, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors.
0