CVE-2015-2945
published 2015-05-25CVE-2015-2945: mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP object injection…
PriorityP274high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.75%
75.0th percentile
mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted request, as exploited in the wild in May 2015.
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jh8x-p66q-m6jw: mt-phpincgi
ghsa_unreviewed·2022-05-17
CVE-2015-2945 [HIGH] CWE-94 GHSA-jh8x-p66q-m6jw: mt-phpincgi
mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted request, as exploited in the wild in May 2015.
VulnCheck
h-fj mt-phpincgi Improper Control of Generation of Code ('Code Injection')
vulncheck·2015·CVSS 7.5
CVE-2015-2945 [HIGH] h-fj mt-phpincgi Improper Control of Generation of Code ('Code Injection')
h-fj mt-phpincgi Improper Control of Generation of Code ('Code Injection')
mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted request, as exploited in the wild in May 2015.
Affected: h-fj mt-phpincgi
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000067.html; https://www.cve.org/CVERecord?id=CVE-2015-2945
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-25
Published
Exploited in the wild