CVE-2015-9227
Status: Analyzed
Last modified:
18-09-2017
Published:
11-09-2017
7.2
SUMMARY CVE-2015-9227
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.
Access CVSS3 CVE-2015-9227
Attack Complexity | Attack Vector | Privileges Required | Scope | User Interaction |
---|---|---|---|---|
LOW | NETWORK | HIGH | UNCHANGED | NONE |
Impact CVSS3 CVE-2015-9227
Confidentiality | Integrity | Availability |
---|---|---|
HIGH | HIGH | HIGH |
Details CVE-2015-9227
EPSS | 0.01649 |
---|---|
EPSS % | 0.87869 |
References | |
CWE | CWE-94 |
CAPEC |
|
Vulnerable Configurations |
|
CVSS3 Source | nvd@nist.gov |
CVSS3 Type | Primary |
CVSS3 Vector | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |