CVE-2015-2945observed exploitation

CVE-2015-2945

Published · Updated

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 1.7%
from disclosure to weapon
Published on NVDMay 25
VulnCheckMay 20
exploitation probability
1.7%top 23% of all CVEs
observed exploitation
yesVulnCheck
mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted request, as exploited in the wild in May 2015.
Affected products
n/a · n/a