Roxy Fileman
Vendor:
First CVE: Jun 7, 2018 · Active for 8 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Roxy Fileman over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2018
8 years ago
Most Recent CVE
Nov 9, 2022
1,353 days ago
CVE Severity & Scoring
Roxy Fileman6 CVEs
33%
67%
All CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20526CRITICAL Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. | Mar 21, 2019 | 9.8 | 84 | NO | YES |
CVE-2018-20525CRITICAL Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. | Mar 21, 2019 | 9.1 | 52 | NO | YES |
CVE-2019-19731HIGH Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for | Dec 16, 2019 | 7.5 | 37 | NO | YES |
CVE-2022-40797CRITICAL Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any | Nov 9, 2022 | 9.8 | 32 | NO | NO |
CVE-2019-7174CRITICAL Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Mov | Apr 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-12042HIGH Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter. | Jun 7, 2018 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· 98th percentile
ExploitDB
3 CVEs
50.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Roxy Fileman
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.4.6 | 1 | 9.8 | 2.6% | 0 | 0 |
| 1.4.5 | 4 | 9.1 | 27.0% | 0 | 3 |