Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown

CVE-2018-19041

Disclosure Date: January 31, 2019 (last updated November 27, 2024)
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
0
Attacker Value
Unknown

CVE-2018-19043

Disclosure Date: January 31, 2019 (last updated November 27, 2024)
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI.
0
Attacker Value
Unknown

CVE-2017-8297

Disclosure Date: April 27, 2017 (last updated November 26, 2024)
A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PHP File Manager" component).
0
Attacker Value
Unknown

CVE-2014-4588

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the Hot Files: File Sharing and Download Manager (wphotfiles) plugin 1.0.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mediaid parameter.
0
Attacker Value
Unknown

CVE-2008-7027

Disclosure Date: August 21, 2009 (last updated October 04, 2023)
Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.
0
Attacker Value
Unknown

CVE-2008-4319

Disclosure Date: September 29, 2008 (last updated October 04, 2023)
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
0
Attacker Value
Unknown

CVE-2005-1956

Disclosure Date: June 12, 2005 (last updated February 22, 2025)
File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.
0