5
CVSSv2

CVE-2019-19731

Published: 16/12/2019 Updated: 23/12/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

roxyfileman roxy fileman 1.4.5

Exploits

Roxy Fileman version 145 for NET suffers from a directory traversal vulnerability ...