Логотип exploitDog
bind:CVE-2015-7309
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-7309

Количество 3

Количество 3

nvd логотип

CVE-2015-7309

около 10 лет назад

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

CVSS2: 6.5
EPSS: Средний
msrc логотип

CVE-2015-7309

3 месяца назад

The theme editor in Bolt allows remote authenticated users to execute arbitrary code by renaming a crafted file

EPSS: Средний
github логотип

GHSA-gfg2-33mf-746p

больше 3 лет назад

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-7309

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

CVSS2: 6.5
60%
Средний
около 10 лет назад
msrc логотип
CVE-2015-7309

The theme editor in Bolt allows remote authenticated users to execute arbitrary code by renaming a crafted file

60%
Средний
3 месяца назад
github логотип
GHSA-gfg2-33mf-746p

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

60%
Средний
больше 3 лет назад

Уязвимостей на страницу