HTTP: Tiny File Manager tinyfilemanager.php fullpath Directory Traversal

This signature detects attempts to exploit a known vulnerability against Tiny File Manager. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.

Affected Products

Tiny_file_manager_project tiny_file_manager

References

CVE: CVE-2021-45010

Short Name
HTTP:DIR:TINY-FLEMNGR-FLPTH-TRV
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2021-45010 Directory File Manager Tiny Traversal fullpath tinyfilemanager.php
Release Date
04/05/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3480
False Positive
Unknown
Vendors

Tiny_file_manager_project

CVSS Score

6.5

Found a potential security threat?