Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)
Metrics
Affected Vendors & Products
References
History
Thu, 01 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2022-11-09T00:00:00.000Z
Updated: 2025-05-01T15:51:32.573Z
Reserved: 2022-09-19T00:00:00.000Z
Link: CVE-2022-40797

Updated: 2024-08-03T12:28:42.623Z

Status : Modified
Published: 2022-11-09T07:15:09.347
Modified: 2025-05-01T16:15:23.130
Link: CVE-2022-40797

No data.