5.5
CVSSv3

CVE-2018-15536

Published: 24/08/2018 Updated: 01/11/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

/filemanager/ajax_calls.php in tecrail Responsive FileManager prior to 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tecrail responsive filemanager

Exploits

The following vulnerabilities were fixed in the version 9134 responsivefilemanagercom #1 Path Traversal Allows to Read Any File Reserved CVE: CVE-2018-15535 Discovered By: Simon Uvarov Vendor Status: Fixed Details: The following request allows a user to read any file on the system GET /filemanager/ajax_callsphp?action=get_fil ...
Responsive FileManager version 9134 suffers from multiple path traversal vulnerabilities ...