Vulnerability Details CVE-2015-6967
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.868
EPSS Ranking 99.4%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2015-6967
-
cpe:2.3:a:nibbleblog:nibbleblog:3.7.1a
-
cpe:2.3:a:nibbleblog:nibbleblog:3.7.1b
-
cpe:2.3:a:nibbleblog:nibbleblog:3.7.1c
-
cpe:2.3:a:nibbleblog:nibbleblog:4.0.1