Record summary

CVE-2018-15535 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBResponsive FileManager < 9.13.4 - Directory TraversalExploitDB exploitby Simon UvarovNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHResponsive FileManager <9.13.4 - Local File InclusionCVSS 7.5

Responsive FileManager before version 9.13.4 is vulnerable to local file inclusion via filemanager/ajax_calls.php because it uses external input to construct a pathname that should be within a restricted directory, aka local file inclusion.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.

Remediation

Upgrade to Responsive FileManager version 9.13.4 or later to fix the vulnerability.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscvecve2018lfiedbsecliststecrailvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:tecrail:responsive_filemanager:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3