CVE-2015-7372: Path Traversal
Published Oct 14, 2015
·Updated
Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the layerstyle parameter.
Affected Software
1 affected component
revive-adserver Revive Adserver<=3.2.1
Remediation
Event History
Oct 14, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7372?
CVE-2015-7372 is considered a high severity vulnerability due to its potential for local file inclusion and remote code execution.
2
How do I fix CVE-2015-7372?
To fix CVE-2015-7372, upgrade Revive Adserver to version 3.2.2 or later to mitigate the directory traversal vulnerability.
3
What systems are affected by CVE-2015-7372?
CVE-2015-7372 affects all versions of Revive Adserver prior to 3.2.2.
4
What type of vulnerability is CVE-2015-7372?
CVE-2015-7372 is a directory traversal vulnerability that allows remote attackers to include and execute arbitrary local files.
5
Can I exploit CVE-2015-7372 remotely?
Yes, CVE-2015-7372 can be exploited remotely by an attacker using specially crafted input.