CVE-2022-46604 affects Tecrail Responsive FileManager (RFM) v9.9.5 and earlier. Based on the provided content, the vulnerability is in the file creation workflow exposed via execute.php?action=create_file. RFM checks the user-controlled name parameter for disallowed extensions, but fails to apply equivalent validation to the path parameter, which is used as the effective filename/path during file creation. An attacker can therefore submit a benign value such as 1.txt in name to satisfy the extension filter while placing a .php filename in path and supplying attacker-controlled PHP code through new_content. This results in creation of a server-executable PHP file and leads to arbitrary code execution on the web server. The content notes testing on versions 9.9.2 and 9.9.5 and states that 9.9.6 contains the fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (exploit.py) and a README.md for CVE-2022-46604, a directory traversal vulnerability in Responsive File Manager version 9.13.4. The exploit leverages the file manager's copy/paste functionality to copy an arbitrary file from the server's filesystem (using directory traversal in the 'path' parameter), paste it into a web-accessible directory, and then retrieve it via HTTP GET. The script attempts to automatically retrieve a PHPSESSID session cookie, but also allows manual input if needed. The README provides background on the vulnerability, usage instructions, and references. The main endpoints targeted are /filemanager/ajax_calls.php, /filemanager/execute.php, /filemanager/dialog.php, and /source/[filename]. The exploit is operational and demonstrates the ability to read arbitrary files from a vulnerable server.
This repository provides a working exploit for CVE-2022-46604, a file creation extension bypass vulnerability in Responsive FileManager version 9.9.5 and below. The main exploit script, 'CVE-2022-46604-exploit.py', is a Python 3 tool that automates the process of exploiting the vulnerability to upload a PHP webshell to the target server. The script first obtains a session cookie from the target's /filemanager/dialog.php endpoint, then uses the /filemanager/execute.php?action=create_file endpoint to upload a PHP webshell disguised as a .txt file (bypassing extension restrictions). If successful, the webshell is accessible at /source/shell.php, allowing the attacker to execute arbitrary system commands via HTTP requests. The repository also includes a Dockerfile for setting up a vulnerable environment, a requirements.txt for dependencies, and a README with usage instructions and references. The exploit is operational and provides a real, interactive webshell if the target is vulnerable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A path traversal vulnerability in Responsive File Manager (version 9.13.4) allows unauthenticated attackers to access arbitrary files on the server by manipulating the path parameter. This can expose sensitive files and potentially be used as a stepping stone for further attacks.
A file creation validation bypass in RFM that allows creation of restricted-extension files such as .php by manipulating the path parameter instead of the checked name parameter, leading to arbitrary file upload and likely remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.