Vulnerability Description
Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pydio | Pydio | <= 6.0.6 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/74596Third Party AdvisoryVDB Entry
- https://pydio.com/en/community/releases/pydio-core/pydio-607-security-releaseRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/74596Third Party AdvisoryVDB Entry
- https://pydio.com/en/community/releases/pydio-core/pydio-607-security-releaseRelease NotesVendor Advisory
FAQ
What is CVE-2015-3431?
CVE-2015-3431 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."
How severe is CVE-2015-3431?
CVE-2015-3431 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-3431?
Check the references section above for vendor advisories and patch information. Affected products include: Pydio Pydio.