CVE-2015-20115

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:*

History

19 Mar 2026, 14:12

Type Values Removed Values Added
CPE cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:*
First Time Nextclickventures realtyscript
Nextclickventures
Summary
  • (es) Next Click Ventures RealtyScript 4.0.2 no sanea correctamente las cargas de archivos, permitiendo a los atacantes almacenar scripts maliciosos a través del parámetro POST file en admin/tools.php. Los atacantes pueden subir archivos que contienen código JavaScript que se ejecuta en el contexto de admin/tools.php cuando es accedido por otros usuarios.
References () https://www.exploit-db.com/exploits/38496 - () https://www.exploit-db.com/exploits/38496 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/realtyscript-stored-cross-site-scripting-via-file-upload-parameter - () https://www.vulncheck.com/advisories/realtyscript-stored-cross-site-scripting-via-file-upload-parameter - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5269.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5269.php - Exploit, Third Party Advisory

16 Mar 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:17

Updated : 2026-03-19 14:12


NVD link : CVE-2015-20115

Mitre link : CVE-2015-20115

CVE.ORG link : CVE-2015-20115


JSON object : View

Products Affected

nextclickventures

  • realtyscript
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')