Tecrail
tecrail
20 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (20)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. |
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution. |
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the pub...Show more |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Mar 30, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one ope...Show more |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Mar 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible...Show more |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Mar 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. F...Show more |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.ph...Show more |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview action. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Feb 25, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass through the delete_folder action in execute.php. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Oct 31, 2018 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Oct 10, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Oct 10, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Aug 24, 2018 N/A· v4 5.5 MEDIUM· v3 5.8 MEDIUM· v2 /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract a...Show more |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Aug 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences...Show more |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Aug 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 /filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value. |
1Tecrail 1Responsive Filemanager Nov 21, 2024 Aug 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. |