PoC Index

CVE-2018-15536

MEDIUM 5.8EPSS 6.4%

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.

CVSS v3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
EPSS
6.41% chance of exploitation in the next 30 days, 93th percentile
Published
2018-08-24
Updated
2024-08-05

ExploitDB entries (1)

References

Related