CVE-2015-5353
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 7.1%
from disclosure to weapon0 days
Published on NVDJul 1
1st PoCJun 30
exploitation probability
7.1%top 6% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tab parameter to admin/.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/37439unverifiedcve_referencepacketstormsecurity.com/files/132478/Novius-OS-5.0.1-elche-XSS-LFI-Open-Redirect.htmlunverifiedcve_referencewww.exploit-db.com/exploits/37439/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://hyp3rlinx.altervista.org/advisories/AS-NOVIUSOS0629.txthttp://packetstormsecurity.com/files/132478/Novius-OS-5.0.1-elche-XSS-LFI-Open-Redirect.htmlhttps://www.exploit-db.com/exploits/37439/http://www.securityfocus.com/archive/1/535876/100/0/threadedhttp://www.securityfocus.com/bid/75533