CVE-2018-15535
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 45%
from disclosure to weapon3 days
Published on NVDAug 24
1st PoC+3d
exploitation probability
45%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45271cve_referencewww.exploit-db.com/exploits/45271/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.