Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2020-10212
Disclosure Date: March 07, 2020 (last updated February 21, 2025)
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an attacker could create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning. NOTE: this issue exists because of an incomplete fix for CVE-2018-14728.
0
Attacker Value
Unknown
CVE-2018-20793
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.
0
Attacker Value
Unknown
CVE-2018-20795
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.
0
Attacker Value
Unknown
CVE-2018-20794
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.
0
Attacker Value
Unknown
CVE-2018-20792
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php.
0
Attacker Value
Unknown
CVE-2018-20791
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview action.
0
Attacker Value
Unknown
CVE-2018-20789
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass through the delete_folder action in execute.php.
0
Attacker Value
Unknown
CVE-2018-20790
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php.
0
Attacker Value
Unknown
CVE-2018-18867
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.
0