CVE-2015-7815: Path Traversal
Published Nov 16, 2015
·Updated
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary local files via the viewDataTable parameter.
Affected Software
1 affected component
Matomo Matomo<=2.14.3
Event History
Nov 16, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7815?
CVE-2015-7815 is classified as a medium severity vulnerability due to its potential for local file inclusion and remote code execution.
2
How do I fix CVE-2015-7815?
To fix CVE-2015-7815, upgrade Piwik to version 2.15.0 or later.
3
What systems are affected by CVE-2015-7815?
CVE-2015-7815 affects Piwik versions prior to 2.15.0.
4
What type of attack does CVE-2015-7815 allow?
CVE-2015-7815 allows attackers to execute arbitrary local files through a directory traversal exploit.
5
Is there a public exploit for CVE-2015-7815?
Yes, there are public exploits available that demonstrate the local file inclusion vulnerability outlined in CVE-2015-7815.