CVE-2015-4118
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.
- Affected products
- Ispconfig
- Ispconfig
- ≤ 3.0.5.4
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2015-06-15
CVE-2015-4118 at NVD
4 known exploits for CVE-2015-4118
Proof-of-concept code and exploit modules indexed by Sploitus