Vulnerabilities > CVE-2015-3203 - Unspecified vulnerability in H5Ai Project H5Ai 0.24.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
h5ai-project
exploit available

Summary

Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the href parameter. <a href="http://cwe.mitre.org/data/definitions/434.html">CWE-434: Unrestricted Upload of File with Dangerous Type</a>

Vulnerable Configurations

Part Description Count
Application
H5Ai_Project
1

Exploit-Db

descriptionh5ai < 0.25.0 - Unrestricted File Upload. CVE-2015-3203. Webapps exploit for php platform
fileexploits/php/webapps/38256.py
idEDB-ID:38256
last seen2016-02-04
modified2015-09-22
platformphp
port80
published2015-09-22
reporterrTheory
sourcehttps://www.exploit-db.com/download/38256/
titleh5ai < 0.25.0 - Unrestricted File Upload
typewebapps