AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-0859

HIGH · CVSS 7.5 EPSS 2.33%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-12-03 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Apache, Debian. It may be remotely exploitable.

CVE
CVE-2015-0859
Severity
HIGH
CVSS
7.5
EPSS
2.33%
Apache Debian

Original NVD Description

The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.