← Vulnerability feed

Vulnerability record · CVE-2018-15535 · published 24 August 2018

CVE-2018-15535: Responsive FileManager ajax_calls.php path traversal allows file read

Tecrail · Responsive Filemanager

tecrail Responsive FileManager before 9.13.4 builds a pathname from external input in /filemanager/ajax_calls.php without neutralizing ".." sequences, so the resolved path can escape the intended restricted directory. This is a classic directory traversal (CWE-22) that exposes files outside the file manager's root.

7.5 CVSS 3.0 High EPSS 45% · top 1.3% CWE-22 · Path traversal
7.5CVSS 3.0 base score, v2 5.0
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable file read with public exploit code and very high EPSS, though limited to confidentiality impact.

What it is

tecrail Responsive FileManager before 9.13.4 builds a pathname from external input in /filemanager/ajax_calls.php without neutralizing ".." sequences, so the resolved path can escape the intended restricted directory. This is a classic directory traversal (CWE-22) that exposes files outside the file manager's root.

Impact

An unauthenticated remote attacker can read files outside the restricted directory, giving access to configuration, credential or source files reachable by the web server process. The CVSS vector shows high confidentiality impact only, with no integrity or availability effect.

Attack surface

Reached over the network via HTTP requests to /filemanager/ajax_calls.php with crafted get_file path parameters; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Public exploit code exists (Exploit-DB 45271 and a Full Disclosure post), and EPSS is 0.45242 (98.7th percentile), indicating high predicted exploitation activity; the CVE is not listed in CISA KEV.

What to do

  • Upgrade tecrail Responsive FileManager to 9.13.4 or later, which fixes the traversal.
  • If upgrade is not possible, restrict or block access to /filemanager/ajax_calls.php and the filemanager directory from untrusted networks.
  • Run the web service with least privilege and confine its filesystem access so traversal cannot reach sensitive paths.
  • Validate and canonicalize any user-supplied path against the allowed base directory before file operations.

Detection

  • Monitor web logs for requests to /filemanager/ajax_calls.php containing ".." or encoded traversal sequences in parameters.
  • Alert on file reads returning content from paths outside the file manager root, especially configuration or credential files.
  • Search for known exploit payload patterns from Exploit-DB 45271 in HTTP request bodies and query strings.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2018/Aug/34 ExploitMailing ListThird Party Advisory
https://www.exploit-db.com/exploits/45271/ ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2018/Aug/34 ExploitMailing ListThird Party Advisory
https://www.exploit-db.com/exploits/45271/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2018-15535 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44276Tecrail responsive filemanager unrestricted file upload vulnerabilityIn Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.EPSS 2.3%9.8CVE-2017-20145Tecrail responsive filemanager path traversal vulnerabilityA vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The att…EPSS 1.0%9.8CVE-2020-10567Tecrail responsive filemanager improper input validation vulnerabilityAn issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is n…EPSS 20%9.8CVE-2020-10212Tecrail responsive filemanager server-side request forgery (ssrf) vulnerabilityupload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it…EPSS 1.5%9.8CVE-2018-14728Responsive FileManager upload.php SSRF via url parameterResponsive FileManager 9.13.1 exposes an SSRF flaw in upload.php through the url parameter, allowing the server to fetch attacker-controlled URLs. Th…EPSS 77%analysed8.8CVE-2022-46604Tecrail responsive filemanager unrestricted file upload vulnerabilityAn issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP fi…EPSS 8.6%8.6CVE-2018-18867Tecrail responsive filemanager server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incompl…EPSS 1.5%7.5CVE-2018-20789Tecrail responsive filemanager path traversal vulnerabilitytecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigati…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2018-15535), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.