CVE-2018-15536
Last modified
CVE-2018-15536 is a vulnerability of currently unknown severity. /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.. EPSS estimates a 6.41% chance of exploitation in the next 30 days.
Description
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tecrail | Responsive Filemanager | < 9.13.4 |
References
- http://seclists.org/fulldisclosure/2018/Aug/34Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/45271/Exploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Aug/34Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/45271/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15536?
How severe is CVE-2018-15536?
How do I fix CVE-2018-15536?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-15530Cross-site scripting (XSS) in the web interface of the Xerox…
- CVE-2018-15531JavaMelody before 1.74.0 has XXE via parseSoapMethodName in …
- CVE-2018-15532SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 al…
- CVE-2018-15533A reflected cross-site scripting vulnerability exists in Geu…
- CVE-2018-15534Geutebrueck re_porter 16 before 7.8.974.20 has a possibility…
- CVE-2018-15535/filemanager/ajax_calls.php in tecrail Responsive FileManage…
- CVE-2018-15537Unrestricted file upload (with remote code execution) in OCS…
- CVE-2018-15538Agentejo Cockpit has multiple Cross-Site Scripting vulnerabi…
- CVE-2018-15539Agentejo Cockpit lacks an anti-CSRF protection mechanism. Th…
- CVE-2018-1554IBM Maximo Asset Management 7.6 is vulnerable to cross-site …5.4
- CVE-2018-15540Agentejo Cockpit performs actions on files without appropria…
- CVE-2018-15542An issue was discovered in the org.telegram.messenger applic…
Are you affected by CVE-2018-15536?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
