9.8
CVSSv3

CVE-2015-8261

Published: 08/01/2016 Updated: 10/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold prior to 16.4 does not properly validate serialized XML objects, which allows remote malicious users to conduct SQL injection attacks via a crafted SOAP request.

Vulnerable Product Search on Vulmon Subscribe to Product

ipswitch whatsup gold 16.3

Exploits

# # Exploit Title: WhatsUp Gold v163 Unauthenticated Remote Code Execution # Date: 2016-01-13 # Exploit Author: Matt Buzanowski # Vendor Homepage: wwwipswitchcom/ # Version: 163x # Tested on: Windows 7 x86 # CVE : CVE-2015-8261 # Usage: python DroneDeleteOldMeasurementspy <target ip> import requests import sys ip_addr = sysarg ...
WhatsUp Gold version 163 suffers from an unauthenticated remote code execution vulnerability ...