/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:54:03.433Z
Reserved: 2018-08-19T00:00:00
Link: CVE-2018-15535
No data.
Status : Modified
Published: 2018-08-24T19:29:01.860
Modified: 2024-11-21T03:51:01.430
Link: CVE-2018-15535
No data.
OpenCVE Enrichment
No data.
Weaknesses