{"api_version":"1","generated_at":"2026-07-23T10:00:02+00:00","cve":"CVE-2015-5951","urls":{"html":"https://cve.report/CVE-2015-5951","api":"https://cve.report/api/cve/CVE-2015-5951.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-5951","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-5951"},"summary":{"title":"CVE-2015-5951","description":"A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-01-06 21:15:00","updated_at":"2020-01-10 19:23:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/76271","name":"http://www.securityfocus.com/bid/76271","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"Thomson Reuters FATCA CVE-2015-5951 Arbitrary File Upload Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://seclists.org/bugtraq/2015/Aug/32","name":"https://seclists.org/bugtraq/2015/Aug/32","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"Bugtraq: Thomson Reuters FATCA - Arbitrary File Upload","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/536163/100/0/threaded","name":"http://www.securityfocus.com/archive/1/536163/100/0/threaded","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/133003/Thomson-Reuters-FATCA-Arbitrary-File-Upload.html","name":"http://packetstormsecurity.com/files/133003/Thomson-Reuters-FATCA-Arbitrary-File-Upload.html","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"Thomson Reuters FATCA Arbitrary File Upload ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2015/Aug/25","name":"http://seclists.org/fulldisclosure/2015/Aug/25","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"Full Disclosure: Thomson Reuters FATCA - Arbitrary File Upload","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-5951","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-5951","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"5951","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"thomsonreuters","cpe5":"fatca","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5951","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"thomsonreuters","cpe5":"fatca","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-5951","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"http://packetstormsecurity.com/files/133003/Thomson-Reuters-FATCA-Arbitrary-File-Upload.html","refsource":"MISC","name":"http://packetstormsecurity.com/files/133003/Thomson-Reuters-FATCA-Arbitrary-File-Upload.html"},{"url":"http://www.securityfocus.com/bid/76271","refsource":"MISC","name":"http://www.securityfocus.com/bid/76271"},{"url":"http://seclists.org/fulldisclosure/2015/Aug/25","refsource":"MISC","name":"http://seclists.org/fulldisclosure/2015/Aug/25"},{"url":"http://www.securityfocus.com/archive/1/536163/100/0/threaded","refsource":"MISC","name":"http://www.securityfocus.com/archive/1/536163/100/0/threaded"},{"refsource":"MISC","name":"https://seclists.org/bugtraq/2015/Aug/32","url":"https://seclists.org/bugtraq/2015/Aug/32"}]}},"nvd":{"publishedDate":"2020-01-06 21:15:00","lastModifiedDate":"2020-01-10 19:23:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.1,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9},"severity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:thomsonreuters:fatca:*:*:*:*:*:*:*:*","versionEndExcluding":"5.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"5951","Ordinal":"82951","Title":"CVE-2015-5951","CVE":"CVE-2015-5951","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"5951","Ordinal":"1","NoteData":"A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"5951","Ordinal":"2","NoteData":"2020-01-06","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"5951","Ordinal":"3","NoteData":"2020-01-06","Type":"Other","Title":"Modified"}]}}}