VDB

GCVE-VVD-MAGEIA-2015-426

GCVE-VVD-MAGEIA-2015-426
Advisory Published
Vulnetix · Advisory published November 4, 2015
Under some situations, the Spring Framework is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response (CVE-2015-5211).

Affected Products

VendorProductVersionsPlatforms
Mageiaspringframework0 (affected), 3.2.15-1.mga5 (unaffected)
Mageiajson-path0 (affected), 0.9.1-1.mga5 (unaffected)
Mageiajson-smart0 (affected), 1.3-0.20140820.1.mga5 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›