Unrated severityNVD Advisory· Published Oct 28, 2015· Updated Jun 17, 2026
CVE-2015-7904
CVE-2015-7904
Description
Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:infinite_automation_systems:mango_automation:2.5.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:infinite_automation_systems:mango_automation:2.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:infinite_automation_systems:mango_automation:2.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:infinite_automation_systems:mango_automation:2.6.0:*:*:*:*:*:*:*
- (no CPE)range: 2.5.x, <2.6.0 build 430
Patches
Vulnerability mechanics
References
1- ics-cert.us-cert.gov/advisories/ICSA-15-300-02nvdPatchThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.