NA

CVE-2022-40797

Published: 09/11/2022 Updated: 31/01/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

roxyfileman roxy fileman 1.4.6

Exploits

Roxy Fileman versions 146 and below remote shell upload proof of concept exploit ...