Security Advisory

CVE-2015-20115

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-15 18:34:13
Last updated 2026-05-24 01:36:07
Assigner VulnCheck
CVSS score 5.1
State PUBLISHED

Description

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users.