CRITICAL

CVE-2015-9263

CVSS v3

9.8

CRITICAL

EPSS Score

64.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.

Technical details

Published
8/27/2018

Frequently asked questions

What is CVE-2015-9263?

An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.

Is CVE-2015-9263 actively exploited?

Active exploitation of CVE-2015-9263 has not been confirmed. The EPSS score is 64.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2015-9263?

CVE-2015-9263 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2015-9263 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.