4.9
CVSSv2

CVE-2015-4425

Published: 18/08/2015 Updated: 19/08/2015
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 495
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.

Vulnerable Product Search on Vulmon Subscribe to Product

pimcore pimcore -

Exploits

Vulnerability title: Directory Traversal/Configuration Update In Pimcore CMS CVE: CVE-2015-4425 Vendor: Pimcore Product: Pimcore CMS Affected version: Build 3450 Fixed version: Build 3473 Reported by: Josh Foote Details: It is possible for an administrative user with the 'assets' permission to overwrite system configuration files via exploiting a ...
Pimcore CMS build 3450 suffers from an issues where it is possible for an administrative user with the 'assets' permission to overwrite system configuration files via exploiting a directory traversal vulnerability ...