← Back

Qto

qto

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qto
1Qtofilemanager
Apr 23, 2026
May 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.
1Qto
1Qtofilemanager
Apr 16, 2026
Jul 7, 2006
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.
1Qto
1Qtofilemanager
Apr 16, 2026
Jul 7, 2006
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.
1Qto
1Qtofilemanager
Apr 16, 2026
Jun 22, 2006
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php.