CVE-2016-15023 - CVE House
Back to Database
Status published Low CVE-2016-15023

SiteFusion Application Server Extension getextension.php path traversal

Vulnerability Description

A vulnerability, which was classified as problematic, was found in SiteFusion Application Server up to 6.6.6. This affects an unknown part of the file getextension.php of the component Extension Handler. The manipulation leads to path traversal. Upgrading to version 6.6.7 is able to address this issue. The identifier of the patch is 49fff155c303d6cd06ce8f97bba56c9084bf08ac. It is recommended to upgrade the affected component. The identifier VDB-219765 was assigned to this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-15023

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • VulDB GitHub Commit Analyzer

Affected Vendor

Affected Software

Application Server
Vulnerable Versions:
6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6

Timeline

Official Publish: January 31st, 2023
Last Modified: August 6th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)