← back
CVE-2018-15535

CVE-2018-15535

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 45%
from disclosure to weapon3 days
Published on NVDAug 24
1st PoC+3d
exploitation probability
45%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.