Known Vulnerabilities for products from Tecrail
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Tecrail".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-46604 json | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and... | 8.8 - HIGH | 2023-02-02 | 2023-11-07 |
| CVE-2022-44276 json | In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. | 9.8 - CRITICAL | 2023-06-28 | 2023-07-05 |
| CVE-2020-11106 json | An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF'... | 6.1 - MEDIUM | 2020-03-30 | 2020-04-01 |
| CVE-2020-10567 json | An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the na... | 9.8 - CRITICAL | 2020-03-14 | 2023-03-07 |
| CVE-2020-10212 json | upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is m... | 9.8 - CRITICAL | 2020-03-07 | 2020-03-09 |
| CVE-2018-20795 json | tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parame... | 7.5 - HIGH | 2019-02-25 | 2019-02-25 |
| CVE-2018-20794 json | tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path tra... | 7.5 - HIGH | 2019-02-25 | 2019-02-25 |
| CVE-2018-20793 json | tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] pa... | 7.5 - HIGH | 2019-02-25 | 2019-02-25 |
| CVE-2018-20792 json | tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path paramet... | 7.5 - HIGH | 2019-02-25 | 2019-02-25 |
| CVE-2018-20791 json | tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandl... | 6.1 - MEDIUM | 2019-02-25 | 2019-02-25 |
| CVE-2018-20790 json | tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path... | 7.5 - HIGH | 2019-02-25 | 2019-02-25 |
| CVE-2018-20789 json | tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0]... | 7.5 - HIGH | 2019-02-25 | 2019-02-25 |
| CVE-2018-18867 json | An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exis... | 8.6 - HIGH | 2018-10-31 | 2018-12-07 |
| CVE-2018-18062 json | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote at... | 6.1 - MEDIUM | 2018-10-10 | 2018-11-28 |
| CVE-2018-18061 json | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interfac... | 7.5 - HIGH | 2018-10-10 | 2018-11-28 |
| CVE-2018-15536 json | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives... | 5.5 - MEDIUM | 2018-08-24 | 2018-11-01 |
| CVE-2018-15535 json | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that ... | 7.5 - HIGH | 2018-08-24 | 2018-10-17 |
| CVE-2018-15495 json | /filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter... | 7.5 - HIGH | 2018-08-18 | 2018-10-19 |
| CVE-2018-14728 json | upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. | 9.8 - CRITICAL | 2018-08-03 | 2019-06-17 |
| CVE-2017-20145 json | A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to... | 9.8 - CRITICAL | 2022-07-25 | 2023-02-21 |
Known software with vulnerabilities from Tecrail
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Tecrail | Responsive Filemanager | .9.10.1 |