CVE-2015-4118
CVE-2015-4118
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/132238/ISPConfig-3.0.5.4p6-SQL-Injection-Cross-Site-Request-Forgery.htmlunverifiedcve_referencewww.exploit-db.com/exploits/37259/unverifiedexploitdbwww.exploit-db.com/exploits/37259unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://bugtracker.ispconfig.org/index.php?do=details&task_id=3898http://packetstormsecurity.com/files/132238/ISPConfig-3.0.5.4p6-SQL-Injection-Cross-Site-Request-Forgery.htmlhttps://www.exploit-db.com/exploits/37259/https://www.htbridge.com/advisory/HTB23260http://www.securityfocus.com/archive/1/535734/100/0/threadedhttp://www.securityfocus.com/bid/75126