Skip to content

Known CVE

Bonita BPM Portal <6.5.3 - Local File Inclusion

Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.

CVE-2015-3897

Medium2015CVSS 5CWE-22

cve2015 · unauth · packetstorm · bonita · lfi · bonitasoft · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website