Files or Directories Accessible to External Parties in Pivotal Spring Framework - CVE-2015-5211
Published: June 8, 2023
Pivotal Spring Framework
Pivotal
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to Reflected File Download (RFD) attack. A remote unauthenticated attacker can perform a Reflected File Download (RFD) attack by tricking victim into opening a specially crafted URL with a batch script extension and then execute arbitrary code on the target system.