« Volver al listado

Roxyfileman

Roxyfileman Roxy Fileman: vulnerabilidades y CVE

Roxyfileman Roxy Fileman tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses0
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-40797Crítica (9.8)2.9%—9 nov 2022
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter…
CVE-2019-19731Alta (7.5)12%—16 dic 2019
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially…
CVE-2019-7174Crítica (9.8)1.7%—9 abr 2019
Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations.
CVE-2018-20526Crítica (9.8)73%—21 mar 2019
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
CVE-2018-20525Crítica (9.1)22%—21 mar 2019
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
CVE-2018-12042Alta (7.5)1.8%—7 jun 2018
Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.