Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
tecrail responsive filemanager 9.13.4 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2020-10212
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename i...
Tecrail Responsive Filemanager 9.13.4
Tecrail Responsive Filemanager 9.14.0
5
CVSSv2
CVE-2018-18867
An SSRF issue exists in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.
Tecrail Responsive Filemanager 9.13.4
5
CVSSv2
CVE-2018-20792
tecrail Responsive FileManager 9.13.4 allows remote malicious users to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php.
Tecrail Responsive Filemanager 9.13.4
5
CVSSv2
CVE-2018-20793
tecrail Responsive FileManager 9.13.4 allows remote malicious users to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.
Tecrail Responsive Filemanager 9.13.4
6.4
CVSSv2
CVE-2018-20789
tecrail Responsive FileManager 9.13.4 allows remote malicious users to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass through the delete_folder action in execute.php.
Tecrail Responsive Filemanager 9.13.4
6.4
CVSSv2
CVE-2018-20790
tecrail Responsive FileManager 9.13.4 allows remote malicious users to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php.
Tecrail Responsive Filemanager 9.13.4
4.3
CVSSv2
CVE-2018-20791
tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview action.
Tecrail Responsive Filemanager 9.13.4
5
CVSSv2
CVE-2018-20794
tecrail Responsive FileManager 9.13.4 allows remote malicious users to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.
Tecrail Responsive Filemanager 9.13.4
5
CVSSv2
CVE-2018-20795
tecrail Responsive FileManager 9.13.4 allows remote malicious users to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.
Tecrail Responsive Filemanager 9.13.4
5.8
CVSSv2
CVE-2018-15536
/filemanager/ajax_calls.php in tecrail Responsive FileManager prior to 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.
Tecrail Responsive Filemanager
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »