Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-2842

Опубликовано: 12 мая 2015
Источник: nvd
CVSS2: 10
EPSS Средний

Описание

Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in sounds/.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:goautodial:goadmin_ce:3.0:*:*:*:*:*:*:*
cpe:2.3:a:goautodial:goadmin_ce:3.3:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.43863
Средний

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in sounds/.

EPSS

Процентиль: 97%
0.43863
Средний

10 Critical

CVSS2

Дефекты

NVD-CWE-Other