Логотип exploitDog
bind:CVE-2015-8684
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-8684

Количество 2

Количество 2

nvd логотип

CVE-2015-8684

около 9 лет назад

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hc2-j336-j495

больше 3 лет назад

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-8684

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.

CVSS3: 6.1
0%
Низкий
около 9 лет назад
github логотип
GHSA-2hc2-j336-j495

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу