← volver
CVE-2015-3884

CVE-2015-3884

23Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendepss 14%
de la publicación al arma0 días
Publicada en NVD17 mar
metasploit14 jun
probabilidad de explotación
14%top 4% de las CVE
explotación observada
noninguna fuente lo reporta
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/attachments/ or uploads/users/.
Productos afectados
n/a · n/a