CVE-2015-4118: SQL Injection
Published Jun 15, 2015
·Updated
SQL injection vulnerability in monitor/showsysstate.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.
Affected Software
1 affected component
ISPConfig ISPConfig<=3.0.5.4
Event History
Jun 15, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4118?
CVE-2015-4118 has a medium severity rating due to the potential for unauthorized SQL command execution.
2
How do I fix CVE-2015-4118?
To fix CVE-2015-4118, upgrade ISPConfig to version 3.0.5.4p7 or later.
3
Who is affected by CVE-2015-4118?
CVE-2015-4118 affects remote authenticated users with monitor permissions in ISPConfig prior to version 3.0.5.4p7.
4
What types of attacks can be executed using CVE-2015-4118?
CVE-2015-4118 allows attackers to execute arbitrary SQL commands, which may compromise the database.
5
Is CVE-2015-4118 related to any other vulnerabilities?
Yes, CVE-2015-4118 can be leveraged by remote attackers using CVE-2015-4119.2.