Back to search
CVE-2015-4118
Published: Jun 15, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150610 Multiple Vulnerabilities in ISPConfig
mailing-list
x_refsource_BUGTRAQ
http://bugtracker.ispconfig.org/index.php?do=details&task_id=3898
x_refsource_CONFIRM
75126
vdb-entry
x_refsource_BID
37259
exploit
x_refsource_EXPLOIT-DB
https://www.htbridge.com/advisory/HTB23260
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now