← Back

Roxyfileman

roxyfileman

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Roxy Fileman
roxy_fileman

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Roxyfileman
1Roxy Fileman
May 1, 2025
Nov 9, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter...Show more
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)Show less
1Roxyfileman
1Roxy Fileman
Jun 17, 2026
Dec 16, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially...Show more
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).Show less
1Roxyfileman
1Roxy Fileman
Jun 17, 2026
Apr 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations.
1Roxyfileman
1Roxy Fileman
Nov 21, 2024
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
1Roxyfileman
1Roxy Fileman
Nov 21, 2024
Mar 21, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
1Roxyfileman
1Roxy Fileman
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.