
Educational exploit for CVE-2022-46604 directory traversal in Responsive File Manager v9.13.4. Includes a modified Python script with automatic cookie retrieval for controlled lab testing.
⚠️ Disclaimer
This repository is intended strictly for educational and research purposes only.
The information and code provided here can be used in controlled environments such as private lab machines.
Unauthorized use of this code against systems you do not own or have explicit permission to test is illegal and unethical.
The author is not responsible for any misuse or damage resulting from this material.
CVE 2022 46604 is a vulnerability found in Responsive File Manager, a file management plugin often integrated into web applications and content management systems. The vulnerability exists in version 9.13.4, where insufficient input validation of the path parameter allows unauthenticated users to perform directory traversal and access sensitive files on the server.
According to the National Vulnerability Database (NVD), the issue has a CVSS v3 base score of 7.5 (High), as it enables unauthorized access to files outside the intended web directory. Successful exploitation can lead to the exposure of configuration files, credentials, or other sensitive data.
This repository includes a modified version of the public exploit from ExploitDB (ID 49359) to enhance its usability.
Target File Manager Interface:
http://[URL]/filemanager/


Save the exploit script as exploit.py and run it with the following syntax:
python3 exploit.py [URL] [path]
# Example:
python3 exploit.py http://192.168.117.145 /etc/passwd

Check out the detailed walkthrough and theory on my Medium post:
👉 Read the blog on Medium