cve/2015/CVE-2015-4118.md
2024-06-18 02:51:15 +02:00

859 B

CVE-2015-4118

Description

SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.

POC

Reference

Github