CVE-2015-9263
9.8
CRITICAL · CVSS 3.0 · EPSS 13.3% (pctl 96)
Patch early
EPSS 13.3% — above the 10% action threshold.
Description
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 13.32% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-08-27 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| idera | uptime infrastructure monitor |
References
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5254.php
- https://www.exploit-db.com/exploits/37888/
- https://www.rapid7.com/db/modules/exploit/multi/http/uptime_file_upload_2
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5254.php
- https://www.exploit-db.com/exploits/37888/
- https://www.rapid7.com/db/modules/exploit/multi/http/uptime_file_upload_2
→ the Explorer · watch your stack · NVD