Vulnerability record · CVE-2015-6967 · published 16 September 2015
CVE-2015-6967: Nibbleblog My Image plugin unrestricted file upload enables code execution
Nibbleblog · Nibbleblog
The My Image plugin in Nibbleblog before 4.0.5 permits uploading files with executable extensions without proper validation. An attacker with administrator access can upload a PHP file and then request it directly, achieving remote code execution on the server.
Description
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityAlthough exploitation requires administrator privileges, public exploits exist and EPSS is very high, making it a significant risk for exposed Nibbleblog instances.
What it is
The My Image plugin in Nibbleblog before 4.0.5 permits uploading files with executable extensions without proper validation. An attacker with administrator access can upload a PHP file and then request it directly, achieving remote code execution on the server.
Impact
An attacker gains arbitrary code execution with the privileges of the web server, allowing full compromise of the Nibbleblog installation and potentially the underlying host.
Attack surface
The vulnerability is reached over the network via the My Image plugin upload functionality. It requires authenticated administrator access; no user interaction beyond the upload and subsequent direct request is needed.
Exploitation
Public exploit references are available, and EPSS indicates a high probability of exploitation activity (0.49308, 98.8th percentile). The CVE is not listed in CISA KEV.
What to do
- Upgrade Nibbleblog to version 4.0.5 or later, which fixes the unrestricted file upload.
- Restrict administrator access to trusted networks and enforce strong authentication.
- Disable or remove the My Image plugin if it is not required.
- Configure the web server to prevent execution of uploaded files in content/private/plugins/my_image/.
- Monitor and audit file uploads for executable extensions.
Detection
- Monitor web server logs for POST requests to the My Image plugin upload endpoint followed by GET requests to content/private/plugins/my_image/image.php.
- Alert on the creation of files with executable extensions (e.g., .php) in the content/private/plugins/my_image/ directory.
- Use file integrity monitoring to detect unexpected changes in plugin directories.
- Review administrator account activity for suspicious uploads or logins from unusual locations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-6967 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-6967), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.