Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2015-2775

HIGH severity · CVSS 7.6 · Path traversal
7.6CVSS HIGH

Summary

Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)8%

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.