ZeroHour

Vulnerabilities

20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-44276
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

NVD description · AI analysis pending
9.82% PoC
  • tecrail responsive filemanager
CVE-2022-46604
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading

An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.

NVD description · AI analysis pending
8.89%
  • tecrail responsive filemanager
CVE-2017-20145
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical.

A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended to upgrade the affected component.

NVD description · AI analysis pending
9.81% PoC
  • tecrail responsive filemanager
CVE-2020-11106
An issue was discovered in Responsive Filemanager through 9.14.0.

An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the "view" action and places a payload in the type parameter, and then returns to the dialog.php page. This occurs because ajax_calls.php was also able to set the $_SESSION['RF']["view_type"] variable, but there it wasn't sanitized.

NVD description · AI analysis pending
6.1<1% PoC
  • tecrail responsive filemanager
CVE-2020-10567
An issue was discovered in Responsive Filemanager through 9.14.0.

An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)

NVD description · AI analysis pending
9.820% PoC
  • tecrail responsive filemanager
CVE-2020-10212
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possibl

upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an attacker could create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning. NOTE: this issue exists because of an incomplete fix for CVE-2018-14728.

NVD description · AI analysis pending
9.81% PoC
  • tecrail responsive filemanager
CVE-2018-20793
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, thr

tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.

NVD description · AI analysis pending
7.5
group max
5% PoC
  • tecrail responsive filemanager
CVE-2018-18867
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter.

An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.

NVD description · AI analysis pending
8.62% PoC
  • tecrail responsive filemanager
CVE-2018-18061
+1 in the same advisory: …18062
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1.

An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • tecrail responsive filemanager
CVE-2018-15535
+1 in the same advisory: …15536
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted direc

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.

NVD description · AI analysis pending
7.5
group max
45% PoC ×2
  • tecrail responsive filemanager
CVE-2018-15495
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec ca

/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.

NVD description · AI analysis pending
7.52% PoC
  • tecrail responsive filemanager
CVE-2018-14728
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

NVD description · AI analysis pending
9.877% PoC ×2
  • tecrail responsive filemanager