← back
CVE-2015-3648

CVE-2015-3648

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 8.1%
exploitation probability
8.1%top 6% of all CVEs
observed exploitation
nono source reports it
Directory traversal vulnerability in pages/setup.php in Montala Limited ResourceSpace before 7.2.6727 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the defaultlanguage parameter.
Affected products
n/a · n/a