Логотип exploitDog
bind:CVE-2015-7309
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-7309

Количество 3

Количество 3

nvd логотип

CVE-2015-7309

больше 10 лет назад

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

CVSS2: 6.5
EPSS: Средний
msrc логотип

CVE-2015-7309

6 месяцев назад

The theme editor in Bolt allows remote authenticated users to execute arbitrary code by renaming a crafted file

EPSS: Средний
github логотип

GHSA-gfg2-33mf-746p

почти 4 года назад

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-7309

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

CVSS2: 6.5
60%
Средний
больше 10 лет назад
msrc логотип
CVE-2015-7309

The theme editor in Bolt allows remote authenticated users to execute arbitrary code by renaming a crafted file

60%
Средний
6 месяцев назад
github логотип
GHSA-gfg2-33mf-746p

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

60%
Средний
почти 4 года назад

Уязвимостей на страницу