Record summary

CVE-2015-3648 has a selected CVSS score of 7.5; EIP currently links 1 Nuclei template.

Description

Directory traversal vulnerability in pages/setup.php in Montala Limited ResourceSpace before 7.2.6727 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the defaultlanguage parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHResourceSpace - Local File inclusionCVSS 7.5

ResourceSpace is prone to a local file-inclusion vulnerability because it fails to sufficiently sanitize user-supplied input.

Impact

An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.

Remediation

Upgrade to the latest version of ResourceSpace to fix the local file inclusion vulnerability.

WeaknessesCWE-22
Authorspikpikcu
Template tagscve2015cvelfiresourcespacepacketstormmontalavuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CPE: cpe:2.3:a:montala:resourcespace:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6