CVE-2015-3884
high · 8.8Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/attachments/ or uploads/users/.
8.8
CVSS
14.4%
EPSS (exploit prob.)
96th
EPSS percentile
2017-03-17
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| qdpm | qdpm | <= 9.1 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/168559/qdPM-9.1-Authenticated-Shell-Upload.html
- http://rossmarks.uk/portfolio.php
- http://rossmarks.uk/whitepapers/qdPM_8.3.txt
- http://packetstormsecurity.com/files/168559/qdPM-9.1-Authenticated-Shell-Upload.html
- http://rossmarks.uk/portfolio.php
- http://rossmarks.uk/whitepapers/qdPM_8.3.txt
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-3884