Product
roxyfileman roxy fileman
6 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-40797
CVE-2019-19731
CVE-2019-7174
CVE-2018-20526
CVE-2018-20525
CVE-2018-12042
all versions
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only
all versions
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via
all versions
Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.p
all versions
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
all versions
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
<= 1.4.5
Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.