Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
filerun filerun vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2017-14738
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
Filerun Filerun
1 EDB exploit
NA
CVE-2007-2470
Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter.
Filerun Filerun
NA
CVE-2007-2469
SQL injection vulnerability in index.php in FileRun 1.0 and previous versions allows remote malicious users to execute arbitrary SQL commands via the fid parameter.
Filerun Filerun
9.8
CVSSv3
CVE-2022-47532
FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users§ion=cpanel&page=list request.
Filerun Filerun 20220519
5.3
CVSSv3
CVE-2019-12458
FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01.
Afian Filerun
1 Github repository
5.3
CVSSv3
CVE-2019-12459
FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01.
Afian Filerun
1 Github repository
7.2
CVSSv3
CVE-2021-35504
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.
Afian Filerun
7.2
CVSSv3
CVE-2021-35505
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.
Afian Filerun
4.3
CVSSv3
CVE-2023-28876
A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows malicious users to delete comments on files uploaded by other users.
Afian Filerun
5.3
CVSSv3
CVE-2019-12457
FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01.
Afian Filerun
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4671
unauthorized
CVE-2024-4776
CVE-2024-3407
CVE-2024-26026
CVE-2024-32888
wireless
CVE-2024-4656
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »