CVE-2015-2993

SysAid < 15.1 - Unauthenticated Arbitrary File Write via fileName Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-2993. Includes Metasploit module auxiliary/admin/http/sysaid_admin_acct.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in SysAid Help Desk 14.4, including unauthenticated administrator account creation, file upload via directory traversal, arbitrary file download, and SQL injection. It provides detailed technical steps and payloads for each vulnerability.

Description

SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.

Exploits (2)

exploitdb WORKING POC
webappshardware
https://www.exploit-db.com/exploits/43885

The exploit demonstrates multiple vulnerabilities in SysAid Help Desk 14.4, including unauthenticated administrator account creation, file upload via directory traversal, arbitrary file download, and SQL injection. It provides detailed technical steps and payloads for each vulnerability.

Classification
Working Poc 100%
Attack Type
Rce | Sqli | Info Leak | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: SysAid Help Desk 14.4
No auth needed
Prerequisites: Network access to the target system
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/sysaid_admin_acct.rb

This Metasploit module exploits an unauthenticated administrator account creation vulnerability in SysAid Help Desk by sending a crafted HTTP GET request to the 'createnewaccount' endpoint. It creates a new admin account with specified credentials, though verification must be done manually.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: SysAid Help Desk 14.4
No auth needed
Prerequisites: Network access to the target SysAid instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jun/8
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535679/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75038

Scores

EPSS 0.7700
EPSS Percentile 99.0%

Details

CWE
CWE-264
Status published
Products (1)
sysaid/sysaid < 15.1
Published Jun 08, 2015
Tracked Since Feb 18, 2026