CVE-2018-12042: Path Traversal
Published Jun 7, 2018
·Updated
Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.
Affected Software
1 affected component
Roxyfileman Roxy Fileman<=1.4.5
Event History
Jun 7, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12042?
CVE-2018-12042 is considered to have a medium severity due to its potential for unauthorized file access.
2
How do I fix CVE-2018-12042?
To fix CVE-2018-12042, update Roxy Fileman to version 1.4.6 or later where this vulnerability is addressed.
3
What impact does CVE-2018-12042 have on affected systems?
CVE-2018-12042 can lead to exposure of sensitive files through directory traversal attacks.
4
Which versions of Roxy Fileman are affected by CVE-2018-12042?
Versions of Roxy Fileman up to and including 1.4.5 are affected by CVE-2018-12042.
5
Is CVE-2018-12042 actively being exploited?
While there are no confirmed reports of active exploitation of CVE-2018-12042, it is advisable to remediate the vulnerability as a precaution.