Loading...
Loading...
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload and execute arbitrary files via a NULL byte after the extension, as demonstrated by a .war%00 file.
June 8, 2015
May 6, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2015-2995
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.