CVE-2015-3203

h5ai <0.25.0 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-3203. PoCs published by rTheory.

AI-analyzed exploit summary This exploit leverages an unrestricted file upload vulnerability in h5ai versions 0.22.0 to 0.24.1 (CVE-2015-3203). It crafts a multipart/form-data POST request to upload an arbitrary file, which can lead to remote code execution if the uploaded file is a malicious script.

Description

Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the href parameter.

Exploits (1)

exploitdb WORKING POC
by rTheory · pythonwebappsphp
https://www.exploit-db.com/exploits/38256

This exploit leverages an unrestricted file upload vulnerability in h5ai versions 0.22.0 to 0.24.1 (CVE-2015-3203). It crafts a multipart/form-data POST request to upload an arbitrary file, which can lead to remote code execution if the uploaded file is a malicious script.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: h5ai < 0.25.0
No auth needed
Prerequisites: Target must have h5ai installed and accessible · Attacker must be able to send HTTP requests to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://larsjung.de/h5ai/cve-2015-3203.txt
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38256/

Scores

EPSS 0.0944
EPSS Percentile 94.8%

Details

Status published
Products (1)
h5ai_project/h5ai < 0.24.1
Published Sep 28, 2015
Tracked Since Feb 18, 2026