Responsive FileManager before version 9.13.4 is vulnerable to local file inclusion via filemanager/ajax_calls.php because it uses external input to construct a pathname that should be within a restricted directory, aka local file inclusion.
id: CVE-2018-15535
info:
name: Responsive FileManager <9.13.4 - Local File Inclusion
author: da
...