Skip to content
Noroxi

roxyfileman records

6 published records for vendor roxyfileman.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19
  3. 22

Bar: total · dark part: CISA KEV.

All records

6 records
  • CVE-2018-20526
    61This week

    Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

    CriticalCVSS 9.8Proof of conceptEPSS 73%

    roxyfileman · roxy filemanMar 21, 2019

  • Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.

    CriticalCVSS 9.1Proof of conceptEPSS 22%

    roxyfileman · roxy filemanMar 21, 2019

  • Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .ph

    CriticalCVSS 9.8No exploitEPSS 3%

    roxyfileman · roxy filemanNov 9, 2022

  • CVE-2019-7174
    39Monitor

    Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Ec

    CriticalCVSS 9.8No exploitEPSS 2%

    roxyfileman · roxy filemanApr 9, 2019

  • Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal.

    HighCVSS 7.5Proof of conceptEPSS 12%

    roxyfileman · roxy filemanDec 16, 2019

  • Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.

    HighCVSS 7.5No exploitEPSS 2%

    roxyfileman · roxy filemanJun 7, 2018