VulnerabilityModified
CVE-2015-2971
Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.
MEDIUM 5.5EPSS 1.57%
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- seeds/acmailer
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN64051989/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000098Vendor Advisory
- http://www.acmailer.jp/info/de.cgi?id=58Vendor Advisory
- http://jvn.jp/en/jp/JVN64051989/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000098Vendor Advisory
- http://www.acmailer.jp/info/de.cgi?id=58Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.