Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-40797 | Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.) NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2019-19731 | Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded). NVD description · AI analysis pending | 7.5 | 12% | PoC |
| — | |
| CVE-2019-7174 | Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and m Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-20526 +1 in the same advisory: …20525 | Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. NVD description · AI analysis pending | 9.8 group max | 73% |
| — | ||
| CVE-2018-12042 | Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter. Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — |