CVE-2015-6967 is an unrestricted file upload vulnerability in the My Image plugin of NibbleBlog before version 4.0.5. The vulnerability allows remote administrators to upload files with executable extensions (such as PHP) without proper validation. Once uploaded, these files can be accessed and executed directly via a predictable URL, leading to arbitrary code execution on the server. The flaw is present because the application fails to validate the file type or extension during the upload process in the My Image plugin (content/private/plugins/my_image/image.php).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit script (CVE-2015-6967.py) and a README.md. The exploit targets Nibbleblog installations vulnerable to CVE-2015-6967, an authenticated file upload vulnerability. The script requires the attacker to provide the target URL, valid Nibbleblog admin credentials, and their own IP and port for the reverse shell. The exploit works by logging into the Nibbleblog admin interface, uploading a PHP reverse shell via the vulnerable plugin configuration, and then triggering the shell to connect back to the attacker's machine. The payload is a standard PHP reverse shell, and the attack is performed over HTTP(S) endpoints exposed by the target. The README provides usage instructions and requirements. The exploit is operational and provides a working reverse shell if the target is vulnerable and the attacker has valid credentials.
This repository provides an operational exploit for CVE-2015-6967, a vulnerability in Nibbleblog (<= 4.0.3) that allows authenticated file upload via the 'my_image' plugin. The main exploit script (exploit.py) is a Python tool that automates the attack: it checks connectivity, logs in to the Nibbleblog admin panel using supplied credentials, uploads a PHP reverse shell (phprevshell.php) via the vulnerable plugin, and then triggers the shell. The PHP payload must be configured with the attacker's IP and port, and a netcat listener should be set up to catch the reverse shell. The repository contains four files: a README with usage instructions, an empty log file, the main Python exploit, and the PHP reverse shell payload. The exploit is operational and provides remote shell access if successful. Key endpoints include the Nibbleblog admin login, the plugin file upload handler, and the location where the shell is accessed after upload.
This repository contains a single Metasploit module (modules/exploits/multi/http/nibbleblog_file_upload.rb) targeting a file upload vulnerability in Nibbleblog 4.0.3 (CVE-2015-6967). The exploit requires valid credentials and the presence of the 'My Image' plugin. It authenticates to the web application, uploads a PHP payload via a vulnerable file upload form, and then executes the payload by accessing it through a predictable URL. The module is weaponized, supporting arbitrary PHP payloads provided by Metasploit, and enables remote code execution on the target server. The main endpoints involved are '/admin.php' for authentication and file upload, and '/content/private/plugins/my_image/image.php' for payload execution. The code is written in Ruby and is structured as a standard Metasploit exploit module.
This repository contains a Python exploit script (exploit.py) targeting Nibbleblog 4.0.3 (CVE-2015-6967), specifically exploiting an arbitrary file upload vulnerability in the 'my_image' plugin. The exploit automates the process of logging into the Nibbleblog admin interface, uploading a user-supplied PHP payload (such as a web shell) via a vulnerable plugin configuration endpoint, and then accessing the uploaded file to trigger code execution. The script requires the target URL, valid admin credentials, and a PHP payload file as input. The README provides usage instructions and an example command. The main exploit logic is contained in exploit.py, which uses the requests library to interact with the target over HTTP. The exploit is operational, as it automates the full attack chain and allows for arbitrary PHP code execution on the target server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.