CVE-2015-7571
HIGH EXPLOITEDYeager CMS 1.2.1 - RCE
Title source: llmDescription
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
Exploits (1)
References (4)
Scores
CVSS v3
7.8
EPSS
0.0334
EPSS Percentile
87.1%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2020-11-22
Classification
CWE
CWE-434
Status
draft
Affected Products (1)
yeager/yeager_cms
Timeline
Published
Aug 07, 2017
Tracked Since
Feb 18, 2026