10
CVSSv2

CVE-2014-8731

Published: 23/03/2017 Updated: 09/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHPMemcachedAdmin 1.2.2 and previous versions allows remote malicious users to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpmemcachedadmin project phpmemcachedadmin

Github Repositories

CVE-2014-8731 - PHPMemcachedAdmin RCE - Proof of Concept

CVE-2014-8731-PoC - PHPMemcachedAdmin Remote Code Execution A proof of concept tool to test your own system if they are vulnerable to CVE-2014-8731 Blog Post PHPMemcachedAdmin Remote Code Execution - CVE-2014-8731 PoC Run test Start victim server: docker run -p8081:80 --rm --name phpma -it alphayax/phpmemcachedadmin Attack victim with PoC: