CVE-2018-15536

MEDIUM

Tecrail Responsive Filemanager < 9.13.4 - Path Traversal

Title source: rule
STIX 2.1

Description

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Simon Uvarov · textwebappsphp
https://www.exploit-db.com/exploits/45271

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45271/
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Aug/34

Scores

CVSS v3 5.5
EPSS 0.0662
EPSS Percentile 91.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (1)
tecrail/responsive_filemanager < 9.13.4
Published Aug 24, 2018
Tracked Since Feb 18, 2026