CVE-2015-2845: OS Command Injection
Published May 12, 2015
·Updated
The cpanel function in gosite.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATHINFO.
Affected Software
2 affected components
GoAutoDial GoAdmin CE=3.0
GoAutoDial GoAdmin CE=3.3
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2845?
CVE-2015-2845 is considered to be of high severity due to its potential to allow remote command execution.
2
How do I fix CVE-2015-2845?
To fix CVE-2015-2845, upgrade to GoAdmin CE version 3.3-1421902800 or later.
3
What types of attacks can CVE-2015-2845 facilitate?
CVE-2015-2845 can facilitate arbitrary command execution attacks by exploiting the cpanel function in go_site.php.
4
Which versions of GoAutoDial are affected by CVE-2015-2845?
CVE-2015-2845 affects GoAutoDial GoAdmin CE versions prior to 3.3-1421902800.
5
What file is primarily affected by the vulnerability in CVE-2015-2845?
The primary file affected by CVE-2015-2845 is go_site.php.