HTTP: Tiny File Manager tinyfilemanager.php fullpath Directory Traversal
This signature detects attempts to exploit a known vulnerability against Tiny File Manager. A successful attack can lead to directory traversal and arbitrary code execution.
Extended Description
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
Affected Products
Tiny_file_manager_project tiny_file_manager
References
CVE: CVE-2021-45010
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Tiny_file_manager_project
6.5