Home/Product/tecrail responsive filemanager
Product

tecrail responsive filemanager

21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-44276
< 9.12.0
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
9.8CRITICAL
CVE-2021-31711
<= 9.4.10
Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to execute a
5.4MEDIUM
CVE-2022-46604
<= 9.9.5
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and uplo
8.8HIGH
CVE-2017-20145
<= 9.11.0
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path
6.3MEDIUM
CVE-2020-11106
<= 9.14.0
An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["vi
6.1MEDIUM
CVE-2020-10567
<= 9.14.0
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name pa
9.8CRITICAL
CVE-2020-10212
all versions
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishan
9.8CRITICAL
CVE-2018-20795
all versions
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter,
7.5HIGH
CVE-2018-20794
all versions
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversa
7.5HIGH
CVE-2018-20793
all versions
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path tr
7.5HIGH
CVE-2018-20792
all versions
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, t
7.5HIGH
CVE-2018-20791
all versions
tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling o
6.1MEDIUM
CVE-2018-20790
all versions
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path trav
7.5HIGH
CVE-2018-20789
all versions
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path
7.5HIGH
CVE-2018-18867
all versions
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists be
8.6HIGH
CVE-2018-18062
all versions
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attacke
6.1MEDIUM
CVE-2018-18061
all versions
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface tha
7.5HIGH
CVE-2018-15536
< 9.13.4
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, all
5.5MEDIUM
CVE-2018-15535
< 9.13.4
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that shoul
7.5HIGH
CVE-2018-15495
< 9.13.3
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is u
7.5HIGH
CVE-2018-14728
all versions
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
9.8CRITICAL
threatengine.sh