CVE-2015-20115
EUVD-2015-941116.03.2026, 14:17
Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users.
Awaiting analysis
This vulnerability is currently awaiting analysis.