CVE-2015-5951
Summary
| CVE | CVE-2015-5951 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-06 21:15:00 UTC |
| Updated | 2020-01-10 19:23:00 UTC |
| Description | A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Thomsonreuters | Fatca | All | All | All | All |
| Application | Thomsonreuters | Fatca | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Thomson Reuters FATCA CVE-2015-5951 Arbitrary File Upload Vulnerability | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Bugtraq: Thomson Reuters FATCA - Arbitrary File Upload | MISC | seclists.org | Mailing List, Third Party Advisory |
| SecurityFocus | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Thomson Reuters FATCA Arbitrary File Upload ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| Full Disclosure: Thomson Reuters FATCA - Arbitrary File Upload | MISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.