Lucene search

K
cve[email protected]CVE-2015-6968
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2015-6968

2022-10-0316:15:53
web.nvd.nist.gov
21
cve
serendipity
blacklist
vulnerabilities
nvd
php code execution

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.8%

Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.2 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .pht or (2) .phtml extension.

Affected configurations

NVD
Node
s9yserendipityRange2.0.1
CPENameOperatorVersion
s9y:serendipitys9y serendipityle2.0.1

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.8%

Related for CVE-2015-6968