CVE-2015-6967
MEDIUM 6.5EPSS 49.3%
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.
- CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 49.31% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2015-09-16
- Updated
- 2024-09-17
Proof-of-concept exploits (5)
- FredBrave/CVE-2015-69670★ · 2023-06-26
- cuerv0x/CVE-2015-69670★ · 2025-06-24
- dix0nym/CVE-2015-696715★ · 2021-02-25
- innocentx0/CVE-2015-6967-EXPLOIT0★ · 2025-08-18
- nirajmaharz/Hackthebox-nibbles-exploit0★ · 2022-11-14