Roxyfileman

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    4
    Critical Level Threats
    2
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-40797

    Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

    Last Modified: May 01, 2025
    Published: Nov 09, 2022

    CVE-2019-19731

    Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

    Last Modified: Nov 21, 2024
    Published: Dec 16, 2019

    CVE-2019-7174

    Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations.

    Last Modified: Nov 21, 2024
    Published: Apr 09, 2019

    CVE-2018-20526

    Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

    Last Modified: Nov 21, 2024
    Published: Mar 18, 2019

    CVE-2018-20525

    Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.

    Last Modified: Nov 21, 2024
    Published: Mar 18, 2019
    Items Per Page
    Roxyfileman Vulnerabilities & Security CVEs | CVE-DB