VulnerabilityModified
CVE-2015-9263
It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
CRITICAL 9.8EPSS 13.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 13.32% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- idera/uptime infrastructure monitor
- Source
- cve@mitre.org
References
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5254.phpExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/37888/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/multi/http/uptime_file_upload_2Third Party Advisory
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5254.phpExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/37888/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/multi/http/uptime_file_upload_2Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.