Known Vulnerabilities for products from Roxyfileman
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Roxyfileman".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-40797 json | Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json ... | 9.8 - CRITICAL | 2022-11-09 | 2023-01-31 |
| CVE-2019-19731 json | Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary location... | 7.5 - HIGH | 2019-12-16 | 2019-12-23 |
| CVE-2019-7174 json | Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), filesl... | 9.8 - CRITICAL | 2019-04-09 | 2020-08-24 |
| CVE-2018-20526 json | Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. | 9.8 - CRITICAL | 2019-03-21 | 2019-03-22 |
| CVE-2018-20525 json | Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. | 9.1 - CRITICAL | 2019-03-21 | 2022-05-13 |
| CVE-2018-12042 json | Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter. | 7.5 - HIGH | 2018-06-07 | 2018-07-17 |
Known software with vulnerabilities from Roxyfileman
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Roxyfileman | Roxy Fileman | 1.0 |