VendorsQtoqtofilemanagerall versions
Vulnerabilities

Qto Qtofilemanager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2008-2110
Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.
Published 2008-05-07 · Modified
7.51 PoCEPSS 0.024
CVE-2006-3406
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.
Published 2006-07-07 · Modified
6.4EPSS 0.014
CVE-2006-3405
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.
Published 2006-07-07 · Modified
5.81 PoCEPSS 0.018
CVE-2006-3132
Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php.
Published 2006-06-22 · Modified
5.8EPSS 0.015