7.5
CVSSv2

CVE-2015-2208

Published: 12/03/2015 Updated: 12/03/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 756
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote malicious users to execute arbitrary commands via shell metacharacters in the object parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

avinu phpmoadmin 1.1.2

Exploits

###################################################################### # _ ___ _ _ ____ ____ _ _____ # | | / _ \| \ | |/ ___|/ ___| / \|_ _| # | | | | | | \| | | _| | / _ \ | | # | |__| |_| | |\ | |_| | |___ / ___ \| | # |_____\___/|_| \_|\____|\____/_/ \_\_| # # PHPMoAdmin Unauthorized Remote Code Execution (0-Day) ...

Github Repositories

BLACKBOx Penetration Testing Framework PASSWORD ATTACKs: MD5, SHA1, SHA224, SHA256, SHA384, SHA512, MSSQL2000, MSSQL2005, MYSQL323, MYSQL41, ORACLE11 CRACKER BRUTEFORCING : Wordpress Bruteforce – Bruteforce wordpress panel FTP Bruteforce – Bruteforcing FTP LOGIN SSH Bruteforce – Bruteforcing SSH LOGIN Admin Page Finder – Find Admin P

BLACKBOx Penetration Testing Framework

BLACKBOx Penetration Testing Framework PASSWORD ATTACKs: MD5, SHA1, SHA224, SHA256, SHA384, SHA512, MSSQL2000, MSSQL2005, MYSQL323, MYSQL41, ORACLE11 CRACKER BRUTEFORCING : Wordpress Bruteforce – Bruteforce wordpress panel FTP Bruteforce – Bruteforcing FTP LOGIN SSH Bruteforce – Bruteforcing SSH LOGIN Admin Page Finder – Find Admin P

Docker simulating cve-2015-2208 vulnerability

#Dockerfile to simulate environment for CVE-2015-2208# The saveObject function in moadminphp in phpMoAdmin 112 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter Discovered by: @u0x (Pichaya Morimoto), Xelenonz, pe3z, Pistachio References: seclistsorg/fulldisclosure/2015/Mar/19 wwwexploit-dbcom/exploits/3