#VU26481 Input validation error in Responsive FileManager - CVE-2020-10567
Published: March 31, 2020
Responsive FileManager
TecRail
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input in the "ajax_calls.php" file in the "save_img" action in the "name" parameter. A remote attacker can execute PHP code if a legitimate JPEG image contains this code in the EXIF data and the .php extension is used in the name parameter.