S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 23, 2024

CVE-2018-20526 Scanner

CVE-2018-20526 scanner - Unrestricted File Upload vulnerability in Roxy Fileman

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-20526
9.8
CVSS

Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Roxy Fileman 1.4.5 is a file management tool that is used to upload and manage files on websites. It is often utilized by web developers and website owners who need an efficient and easy-to-use tool to upload, organize, and delete files on their sites. Roxy Fileman can be accessed through the web browser, and it offers a user-friendly interface that simplifies tasks such as file browsing, uploading, and editing.

CVE-2018-20526 is a critical vulnerability that has been discovered in Roxy Fileman 1.4.5. The vulnerability arises from the fact that the product does not validate the file type while uploading a file, leading to the potential for attackers to upload malicious files to the website. Attackers can exploit this vulnerability to upload and run arbitrary code on the vulnerable server, which can result in the complete compromise of the system.

When this vulnerability is exploited, attackers can take control of the vulnerable server remotely, access sensitive user information, and even steal data or encryption keys. Additionally, attackers can use the compromised server to launch further attacks against other systems. This vulnerability is a severe threat, and it is vital to take proactive measures to mitigate the risk of an attack.

Thanks to the pro features of the s4e.io platform, website owners and developers can easily and quickly learn about vulnerabilities in their digital assets. This platform provides a comprehensive suite of tools and services, including vulnerability scans, penetration testing, and threat intelligence feeds, to help safeguard against cyber threats. By utilizing these features, website owners and developers can ensure that their digital assets are secure and protected against potential cyber attacks.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against this vulnerability:

  • Upgrading Roxy Fileman 1.4.5 to the latest version with the vulnerability patched.
  • Implementing strict file type and size restrictions on the server-side to prevent unauthorized file uploads.
  • Implementing access controls, such as IP whitelisting or user authentication, to limit who can access the vulnerable server.
  • Monitoring the server logs for any suspicious activity or unauthorized access attempts.
  • Conducting regular vulnerability scans and penetration tests to identify and mitigate any other potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-20526 scanner - Unrestricted File Upload vulnerability in Roxy Fileman S4E