CVE-2015-9538: Path Traversal
Published Nov 26, 2019
·Updated
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress<2.1.15
Event History
Nov 26, 2019
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
Description
Frequently Asked Questions
1
What is CVE-2015-9538?
CVE-2015-9538 is a vulnerability in the NextGEN Gallery plugin for WordPress that allows directory traversal in path selection.
2
How severe is CVE-2015-9538?
CVE-2015-9538 has a severity keyword of medium and a severity value of 6.5.
3
Which software versions are affected by CVE-2015-9538?
The NextGEN Gallery plugin versions up to and excluding 2.1.15 for WordPress are affected by CVE-2015-9538.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2015-9538?
CVE-2015-9538 is associated with CWE-22, which is the classification for path traversal and file inclusion vulnerabilities.
5
How can I fix CVE-2015-9538?
To fix CVE-2015-9538, you should update the NextGEN Gallery plugin to version 2.1.15 or newer.