fomori.orgConfirmation
http://www.fomori.org/cherrymusic/Changes.html CVE-2015-8309
Cherry Music directory traversal vulnerability
Record summary
EIP currently links 1 catalogued exploit to CVE-2015-8309.
Description
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CherryMusicBrowse PyPI / CherryMusic | GitHub Advisory | Before 0.36.0 · Fixed in 0.36.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCherry Music 0.35.1 - Arbitrary File DisclosureExploitDB exploitby feedersecNot analyzed1 file
References
997149vdb entry
http://www.securityfocus.com/bid/97149 github.com
https://github.com/devsnd/cherrymusic github.comConfirmation
https://github.com/devsnd/cherrymusic/commit/62dec34a1ea0741400dd6b6c660d303dcd651e86 github.comConfirmation
https://github.com/devsnd/cherrymusic/issues/598 github.com
https://github.com/pypa/advisory-database/tree/main/vulns/cherrymusic/PYSEC-2017-99.yaml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-8309 web.archive.org
https://web.archive.org/web/20200227183321/http://www.securityfocus.com/bid/97149 40361exploit
https://www.exploit-db.com/exploits/40361