CVE-2015-2844: OS Command Injection
Published May 12, 2015
·Updated
The cpanel function in gosite.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATHINFO.
Affected Software
2 affected components
GoAutoDial GoAdmin CE=3.0
GoAutoDial GoAdmin CE=3.3
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2844?
CVE-2015-2844 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2015-2844?
Fixing CVE-2015-2844 involves updating GoAutoDial GoAdmin CE to versions 3.3-1420434000 or later.
3
What systems are affected by CVE-2015-2844?
CVE-2015-2844 affects GoAutoDial GoAdmin CE versions 3.0 and 3.3 prior to the specified patched version.
4
Can CVE-2015-2844 lead to data breaches?
Yes, CVE-2015-2844 can lead to unauthorized data access and potential breaches due to arbitrary command execution capabilities.
5
Who is vulnerable to CVE-2015-2844?
Organizations using vulnerable versions of GoAutoDial GoAdmin CE are at risk of exploitation through CVE-2015-2844.