Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Responsive Filemanager CRITICAL 9.8
CVE-2022-44276

In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

Fix: 9.12.0+
Fix from $2,300 2023-06-28
Responsive Filemanager HIGH 8.8
CVE-2022-46604EPSS 9%

An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP fi…

Fix: after 9.9.5
Fix from $1,950 2023-02-02
Responsive Filemanager CRITICAL 9.8
CVE-2017-20145

A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The att…

Fix: after 9.11.0
Fix from $2,300 2022-07-25
Responsive Filemanager MEDIUM 6.1
CVE-2020-11106

An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sa…

Fix: after 9.14.0
Fix from $1,600 2020-03-30
Responsive Filemanager CRITICAL 9.8
CVE-2020-10567EPSS 19%

An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is n…

Fix: after 9.14.0
Fix from $2,300 2020-03-14
Responsive Filemanager CRITICAL 9.8
CVE-2020-10212

upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it…

No fix yet
Fix from $2,300 2020-03-07
Responsive Filemanager HIGH 7.5
CVE-2018-20789

tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigati…

No fix yet
Fix from $1,950 2019-02-25
Responsive Filemanager HIGH 7.5
CVE-2018-20790

tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation by…

No fix yet
Fix from $1,950 2019-02-25
Responsive Filemanager HIGH 7.5
CVE-2018-20792

tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file…

No fix yet
Fix from $1,950 2019-02-25
Responsive Filemanager HIGH 7.5
CVE-2018-20793

tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation …

No fix yet
Fix from $1,950 2019-02-25
Responsive Filemanager HIGH 7.5
CVE-2018-20794

tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path par…

No fix yet
Fix from $1,950 2019-02-25
Responsive Filemanager HIGH 7.5
CVE-2018-20795

tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cu…

No fix yet
Fix from $1,950 2019-02-25
Responsive Filemanager MEDIUM 6.1
CVE-2018-20791

tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview…

No fix yet
Fix from $1,600 2019-02-25
Responsive Filemanager HIGH 8.6
CVE-2018-18867

An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incompl…

No fix yet
Fix from $1,950 2018-10-31
Responsive Filemanager HIGH 7.5
CVE-2018-18061

An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them wit…

No fix yet
Fix from $1,950 2018-10-10
Responsive Filemanager MEDIUM 6.1
CVE-2018-18062

An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitr…

No fix yet
Fix from $1,600 2018-10-10
Responsive Filemanager HIGH 7.5
CVE-2018-15535EPSS 45%

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restr…

Fix: 9.13.4+
Fix from $1,950 2018-08-24
Responsive Filemanager MEDIUM 5.5
CVE-2018-15536EPSS 6%

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extra…

Fix: 9.13.4+
Fix from $1,600 2018-08-24
Responsive Filemanager HIGH 7.5
CVE-2018-15495

/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a c…

Fix: 9.13.3+
Fix from $1,950 2018-08-18
Responsive Filemanager CRITICAL 9.8
CVE-2018-14728EPSS 77%

upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

No fix yet
Fix from $2,300 2018-08-03