AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-3640

HIGH · CVSS 7.5 EPSS 1.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-07-21 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2015-3640
Severity
HIGH
CVSS
7.5
EPSS
1.23%

Original NVD Description

phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.

Related CVEs

Other vulnerabilities affecting the same vendor(s)