Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-7675

EPSS 0.01% · P1
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-7675

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Ipswitch MOVEit DMZ和MOVEit Mobile 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Ipswitch MOVEit美国Ipswitch公司的一套自动化的文件传输系统。该系统支持通过一个单一的、安全的系统控制、管理,查看所有的关键业务文件传输活动。DMZ和Mobile是其中的版本。 Ipswitch MOVEit DMZ 8.2之前版本和MOVEit Mobile 1.2.2之前版本的‘Send as attachment’功能中存在安全漏洞,该漏洞源于mobile/sendMsg URI没有充分过滤‘serverFileIds’参数;human.aspx文件没有充分过滤‘arg01’参数
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-7675

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-7675

登录查看更多情报信息。

Same Patch Batch · n/a · 2016-02-10 · 71 CVEs total

CVE-2016-0956Adobe Experience Manager Apache Sling Servlets Post组件安全漏洞
CVE-2016-0981多款Adobe产品安全漏洞
CVE-2016-0979多款Adobe产品安全漏洞
CVE-2016-0968多款Adobe产品安全漏洞
CVE-2016-0967多款Adobe产品安全漏洞
CVE-2016-0966多款Adobe产品安全漏洞
CVE-2016-0965多款Adobe产品安全漏洞
CVE-2016-0964多款Adobe产品安全漏洞
CVE-2016-0958Adobe Experience Manager 安全漏洞
CVE-2016-0957Adobe Experience Manager Dispatcher 安全漏洞
CVE-2016-0969多款Adobe产品安全漏洞
CVE-2016-0955Adobe Experience Manager 跨站脚本漏洞
CVE-2016-0953Adobe Photoshop CC和Bridge CC 安全漏洞
CVE-2016-0952Adobe Photoshop CC和Bridge CC 安全漏洞
CVE-2016-0951Adobe Photoshop CC和Bridge CC 安全漏洞
CVE-2016-0950Adobe Connect 安全漏洞
CVE-2016-0949Adobe Connect 安全漏洞
CVE-2016-0948Adobe Connect 跨站请求伪造漏洞
CVE-2015-7680Ipswitch MOVEit DMZ 安全漏洞
CVE-2015-7679Ipswitch MOVEit Mobile 跨站脚本漏洞

Showing top 20 of 71 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2015-7675

No comments yet


Leave a comment