Record summary

EIP currently links 1 catalogued exploit to CVE-2015-8309.

Description

Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 0.36.0 · Fixed in 0.36.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBCherry Music 0.35.1 - Arbitrary File DisclosureExploitDB exploitby feedersecNot analyzed1 file
ExploitDB

PoC details

References

9