CVE-2015-3203

h5ai <0.25.0 - RCE

Title source: llm
STIX 2.1

Description

Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the href parameter.

Exploits (1)

exploitdb WORKING POC
by rTheory · pythonwebappsphp
https://www.exploit-db.com/exploits/38256

Scores

EPSS 0.1236
EPSS Percentile 93.9%

Details

Status published
Products (1)
h5ai_project/h5ai < 0.24.1
Published Sep 28, 2015
Tracked Since Feb 18, 2026