CVE-2015-2843: SQL Injection
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) userpass parameter in gologin.php or the PATHINFO to (3) gologin/validatecredentials/admin/ or (4) index.php/gosite/gogetuserinfo/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2843?
CVE-2015-2843 is classified as a critical SQL injection vulnerability that can allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2015-2843?
To fix CVE-2015-2843, upgrade to a patched version of GoAutoDial GoAdmin CE that addresses these SQL injection vulnerabilities.
What are the affected versions by CVE-2015-2843?
The affected versions of GoAutoDial GoAdmin CE include version 3.0 and all versions before 3.3-1421902800.
Can CVE-2015-2843 be exploited remotely?
Yes, CVE-2015-2843 can be exploited remotely by attackers who send specially crafted SQL queries through the vulnerable parameters.
What parameters are vulnerable in CVE-2015-2843?
The vulnerable parameters in CVE-2015-2843 are user_name, user_pass in go_login.php, and the PATH_INFO for go_login/validate_credentials/admin/ or index.php/go_site/go_get.