CVE-2015-6967
Nibbleblog < 4.0.4 - Unrestricted File Upload
Title source: ruleDescription
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.
Exploits (8)
github
WORKING POC
20 stars
by flex0geek · cpoc
https://github.com/flex0geek/cves-exploits/tree/main/CVE-2015-6967
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38489
metasploit
WORKING POC
EXCELLENT
by Unknown, s name? · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/nibbleblog_file_upload.rb
References (4)
Scores
EPSS
0.8076
EPSS Percentile
99.1%
Classification
Status
draft
Affected Products (1)
nibbleblog/nibbleblog
< 4.0.4
Timeline
Published
Sep 16, 2015
Tracked Since
Feb 18, 2026