Tecrail records
20 published records for vendor tecrail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')10
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2018-14728Proof of concept | upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.tecrail · responsive filemanager · CWE-918 | Critical9.8 | — | 76.5% | Aug 3, 2018 |
45Plan | CVE-2020-10567Proof of concept | An issue was discovered in Responsive Filemanager through 9.14.0.tecrail · responsive filemanager · CWE-20 | Critical9.8 | — | 19.6% | Mar 14, 2020 |
44Plan | CVE-2018-15535Proof of concept | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be withitecrail · responsive filemanager · CWE-22 | High7.5 | — | 45.2% | Aug 24, 2018 |
40Plan | CVE-2022-44276Proof of concept | In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.tecrail · responsive filemanager · CWE-434 | Critical9.8 | — | 2.3% | Jun 28, 2023 |
39Monitor | CVE-2020-10212No exploit | upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and btecrail · responsive filemanager · CWE-918 | Critical9.8 | — | 1.5% | Mar 6, 2020 |
39Monitor | CVE-2017-20145No exploit | Tecrail Responsive Filemanger path traversaltecrail · responsive filemanager · CWE-22 | Critical9.8 | — | 1.0% | Jul 25, 2022 |
38Monitor | CVE-2022-46604Proof of concept | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafttecrail · responsive filemanager · CWE-434 | High8.8 | — | 8.6% | Feb 2, 2023 |
34Monitor | CVE-2018-18867No exploit | An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter.tecrail · responsive filemanager · CWE-918 | High8.6 | — | 1.5% | Oct 31, 2018 |
31Monitor | CVE-2018-20793No exploit | tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitecrail · responsive filemanager · CWE-22 | High7.5 | — | 5.0% | Feb 25, 2019 |
31Monitor | CVE-2018-20794No exploit | tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with thetecrail · responsive filemanager · CWE-22 | High7.5 | — | 4.0% | Feb 25, 2019 |
31Monitor | CVE-2018-20790No exploit | tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mititecrail · responsive filemanager · CWE-22 | High7.5 | — | 3.6% | Feb 25, 2019 |
31Monitor | CVE-2018-20789No exploit | tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversaltecrail · responsive filemanager · CWE-22 | High7.5 | — | 3.6% | Feb 25, 2019 |
31Monitor | CVE-2018-20792No exploit | tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through thetecrail · responsive filemanager · CWE-22 | High7.5 | — | 3.5% | Feb 25, 2019 |
31Monitor | CVE-2018-20795No exploit | tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through thtecrail · responsive filemanager · CWE-22 | High7.5 | — | 3.5% | Feb 25, 2019 |
31Monitor | CVE-2018-15495No exploit | /filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directtecrail · responsive filemanager · CWE-22 | High7.5 | — | 2.4% | Aug 17, 2018 |
30Monitor | CVE-2018-18061No exploit | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1.tecrail · responsive filemanager · CWE-287 | High7.5 | — | 0.9% | Oct 10, 2018 |
24Monitor | CVE-2018-15536Proof of concept | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for tecrail · responsive filemanager · CWE-22 | Medium5.5 | — | 6.4% | Aug 24, 2018 |
24Monitor | CVE-2020-11106No exploit | An issue was discovered in Responsive Filemanager through 9.14.0.tecrail · responsive filemanager · CWE-79 | Medium6.1 | — | 0.9% | Mar 30, 2020 |
24Monitor | CVE-2018-20791No exploit | tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the meditecrail · responsive filemanager · CWE-79 | Medium6.1 | — | 0.8% | Feb 25, 2019 |
24Monitor | CVE-2018-18062No exploit | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1.tecrail · responsive filemanager · CWE-79 | Medium6.1 | — | 0.8% | Oct 10, 2018 |
- CVE-2018-1472862This week
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
CriticalCVSS 9.8Proof of conceptEPSS 77%tecrail · responsive filemanagerAug 3, 2018
- CVE-2020-1056745Plan
An issue was discovered in Responsive Filemanager through 9.14.0.
CriticalCVSS 9.8Proof of conceptEPSS 20%tecrail · responsive filemanagerMar 14, 2020
- CVE-2018-1553544Plan
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be withi
HighCVSS 7.5Proof of conceptEPSS 45%tecrail · responsive filemanagerAug 24, 2018
- CVE-2022-4427640Plan
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
CriticalCVSS 9.8Proof of conceptEPSS 2%tecrail · responsive filemanagerJun 28, 2023
- CVE-2020-1021239Monitor
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and b
CriticalCVSS 9.8No exploitEPSS 1%tecrail · responsive filemanagerMar 6, 2020
- CVE-2017-2014539Monitor
Tecrail Responsive Filemanger path traversal
CriticalCVSS 9.8No exploitEPSS 1%tecrail · responsive filemanagerJul 25, 2022
- CVE-2022-4660438Monitor
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a craft
HighCVSS 8.8Proof of conceptEPSS 9%tecrail · responsive filemanagerFeb 2, 2023
- CVE-2018-1886734Monitor
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter.
HighCVSS 8.6No exploitEPSS 2%tecrail · responsive filemanagerOct 31, 2018
- CVE-2018-2079331Monitor
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mi
HighCVSS 7.5No exploitEPSS 5%tecrail · responsive filemanagerFeb 25, 2019
- CVE-2018-2079431Monitor
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the
HighCVSS 7.5No exploitEPSS 4%tecrail · responsive filemanagerFeb 25, 2019
- CVE-2018-2079031Monitor
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal miti
HighCVSS 7.5No exploitEPSS 4%tecrail · responsive filemanagerFeb 25, 2019
- CVE-2018-2078931Monitor
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal
HighCVSS 7.5No exploitEPSS 4%tecrail · responsive filemanagerFeb 25, 2019
- CVE-2018-2079231Monitor
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the
HighCVSS 7.5No exploitEPSS 3%tecrail · responsive filemanagerFeb 25, 2019
- CVE-2018-2079531Monitor
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through th
HighCVSS 7.5No exploitEPSS 3%tecrail · responsive filemanagerFeb 25, 2019
- CVE-2018-1549531Monitor
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used direct
HighCVSS 7.5No exploitEPSS 2%tecrail · responsive filemanagerAug 17, 2018
- CVE-2018-1806130Monitor
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1.
HighCVSS 7.5No exploitEPSS 1%tecrail · responsive filemanagerOct 10, 2018
- CVE-2018-1553624Monitor
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for
MediumCVSS 5.5Proof of conceptEPSS 6%tecrail · responsive filemanagerAug 24, 2018
- CVE-2020-1110624Monitor
An issue was discovered in Responsive Filemanager through 9.14.0.
MediumCVSS 6.1No exploitEPSS 1%tecrail · responsive filemanagerMar 30, 2020
- CVE-2018-2079124Monitor
tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the medi
MediumCVSS 6.1No exploitEPSS 1%tecrail · responsive filemanagerFeb 25, 2019
- CVE-2018-1806224Monitor
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1.
MediumCVSS 6.1No exploitEPSS 1%tecrail · responsive filemanagerOct 10, 2018