Sploitus

CVE-2015-2295

4 known exploits for CVE-2015-2295

Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter.

Affected products
Pfsense
Netgate Pfsense
≤ 2.2
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
65.7% (99th percentile)
Weakness
CWE-352
NVD status
Modified
Published
2015-04-10
CVE-2015-2295 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2015-2295

Proof-of-concept code and exploit modules indexed by Sploitus