This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:DIR:FILEMGR-DIRTRV
|
Severity |
Major
|
Recommended |
Yes
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Responsive FileManager Zip Directory Traversal
|
Release Date |
2018/11/29
|
Update Number |
3121
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Responsive FileManager Zip Directory Traversal
A zip directory traversal vulnerability has been reported in Responsive FileManager. Successful exploitation could result in the creation or overwriting of files writable by the user running FileManager, leading to the possibility of arbitrary code execution.
Extended Description
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.
Affected Products
- Tecrail responsive_filemanager 9.10.0
- Tecrail responsive_filemanager .9.10.1
- Tecrail responsive_filemanager 9.10.1
- Tecrail responsive_filemanager 9.10.2
- Tecrail responsive_filemanager 9.11.0
- Tecrail responsive_filemanager 9.11.3
- Tecrail responsive_filemanager 9.12.0
- Tecrail responsive_filemanager 9.12.1
- Tecrail responsive_filemanager 9.12.2
- Tecrail responsive_filemanager 9.13.0
- Tecrail responsive_filemanager 9.13.1
- Tecrail responsive_filemanager 9.13.3
- Tecrail responsive_filemanager .9.14.0
- Tecrail responsive_filemanager 9.6.0
- Tecrail responsive_filemanager 9.7.2
- Tecrail responsive_filemanager 9.7.3
- Tecrail responsive_filemanager 9.8
- Tecrail responsive_filemanager 9.8.1
- Tecrail responsive_filemanager 9.9.0
- Tecrail responsive_filemanager 9.9.1
- Tecrail responsive_filemanager 9.9.2
- Tecrail responsive_filemanager 9.9.3
- Tecrail responsive_filemanager 9.9.4
- Tecrail responsive_filemanager 9.9.5
- Tecrail responsive_filemanager 9.9.6
- Tecrail responsive_filemanager 9.9.7
References