6.5
CVSSv2

CVE-2015-7901

Published: 28/10/2015 Updated: 16/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 660
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Infinite Automation Mango Automation 2.5.x and 2.6.x up to and including 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

infinite automation systems mango automation 2.5.0

infinite automation systems mango automation 2.5.5

infinite automation systems mango automation 2.6.0

Exploits

require 'msf/core' class MetasploitModule < Msf::Auxiliary Rank = GreatRanking include Msf::Exploit::Remote::HttpClient def initialize(info = {}) super(update_info(info, 'Name' => 'Infinite Automation Mango Automation Command Injection', 'Description' => %q{ This module exploits a command injection vulnerabil ...
Mango Automation 260 CSRF File Upload And Arbitrary JSP Code Execution Vendor: Infinite Automation Systems Inc Product web page: wwwinfiniteautomationcom/ Affected version: 252 and 260 beta (build 327) Summary: Mango Automation is a flexible SCADA, HMI And Automation software application that allows you to view, log, graph, anima ...