CVE-2015-4393

The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
services_projectservices
7.x-3.0:x
services_projectservices
7.x-3.1:x
services_projectservices
7.x-3.2:x
services_projectservices
7.x-3.3:x
services_projectservices
7.x-3.4:x
services_projectservices
7.x-3.5:x
services_projectservices
7.x-3.6:x
services_projectservices
7.x-3.7:x
services_projectservices
7.x-3.9:x
services_projectservices
7.x-3.10:x
services_projectservices
7.x-3.11:x
𝑥
= Vulnerable software versions