CVE-2018-20525
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 22%
from disclosure to weapon0 days
Published on NVDMar 18
1st PoCJan 7
exploitation probability
22%top 3% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
Affected products
n/a · n/apublic PoCs found — 4
cve_referencepacketstormsecurity.com/files/151033/Roxy-Fileman-1.4.5-File-Upload-Directory-Traversal.htmlunverifiedcve_referencepacketstormsecurity.com/files/166585/Roxy-File-Manager-1.4.5-PHP-File-Upload-Restriction-Bypass.htmlunverifiedcve_referencewww.exploit-db.com/exploits/46085/unverifiedexploitdbwww.exploit-db.com/exploits/46085unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.