CVE-2019-19731

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:roxyfileman:roxy_fileman:1.4.5:*:*:*:*:*:*:*

Information

Published : 2019-12-16 09:15

Updated : 2019-12-23 11:12


NVD link : CVE-2019-19731

Mitre link : CVE-2019-19731


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

roxyfileman

  • roxy_fileman