vendor:
Roxy Fileman
by:
Tyrell Sassen
N/A
CVSS
N/A
Forbidden File Upload
Unknown
CWE
Product Name: Roxy Fileman
Affected Version From: 1.4.2004
Affected Version To: 1.4.2004
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: PHP
2016
Roxy Fileman <= 1.4.4 Forbidden File Upload Vulnerability
The Roxy File Manager has a configuration setting named FORBIDDEN_UPLOADS, which keeps a list of forbidden file extensions that the application will not allow to be uploaded. This configuration setting is also checked when renaming an existing file to a new file extension. It is possible to bypass this check and rename already uploaded files to any extension, using the move function as this function does not perform any checks.
Mitigation:
Unknown