packetstormsecurity.com
http://packetstormsecurity.com/files/148742/Responsive-Filemanager-9.13.1-Server-Side-Request-Forgery.html CVE-2018-14728
CRITICALNuclei
Responsive Filemanager 9.13.1 - Server-Side Request Forgery
Record summary
CVE-2018-14728 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBResponsive Filemanager 9.13.1 - Server-Side Request ForgeryExploitDB exploitby GUIA BRAHIM FOUADNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALResponsive filemanager 9.13.1 Server-Side Request ForgeryCVSS 9.8
Responsive filemanager 9.13.1 is susceptible to server-side request forgery in upload.php via the url parameter.
Impact
An attacker can exploit this vulnerability to bypass security controls, access internal resources, and potentially perform further attacks.
Remediation
Upgrade to a patched version of Responsive Filemanager or apply the necessary security patches to mitigate the SSRF vulnerability.
WeaknessesCWE-918
Authorsmadrobot
Template tagscve2018cvessrflfipacketstormedbintrusivetecrailvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:tecrail:responsive_filemanager:9.13.1:*:*:*:*:*:*:*
http://packetstormsecurity.com/files/148742/Responsive-Filemanager-9.13.1-Server-Side-Request-Forgery.html https://www.exploit-db.com/exploits/45103/ https://nvd.nist.gov/vuln/detail/CVE-2018-14728 https://github.com/sobinge/nuclei-templates https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-14728 45103exploit
https://www.exploit-db.com/exploits/45103