CVE-2015-1577
u5CMS <3.9.4 - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to arbitrary files via a (1) .. (dot dot) or (2) full pathname in the f parameter.
Exploits (2)
Scores
EPSS
0.1030
EPSS Percentile
93.1%
Classification
CWE
CWE-22
Status
draft
Affected Products (1)
yuba/u5cms
< 3.9.3
Timeline
Published
Feb 11, 2015
Tracked Since
Feb 18, 2026