Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-2994

Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp extension, then accessing it via a direct request to the file in icons/user_photo/.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.781
EPSS Ranking 98.9%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2015-2994
  • Sysaid » Sysaid » Version: N/A
    cpe:2.3:a:sysaid:sysaid:-
  • Sysaid » Sysaid » Version: 14.4
    cpe:2.3:a:sysaid:sysaid:14.4
  • Sysaid » Sysaid » Version: 15.1
    cpe:2.3:a:sysaid:sysaid:15.1
  • Sysaid » Sysaid » Version: 6.0
    cpe:2.3:a:sysaid:sysaid:6.0
  • Sysaid » Sysaid » Version: 6.5
    cpe:2.3:a:sysaid:sysaid:6.5


Contact Us

Shodan ® - All rights reserved