Vulnerabilities > CVE-2015-2842 - Multiple Security vulnerability in GoAutoDial GoAdmin CE 3.0/3.3

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
goautodial
critical
exploit available

Summary

Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in sounds/. <a href="http://cwe.mitre.org/data/definitions/434.html">CWE-434: Unrestricted Upload of File with Dangerous Type</a>

Vulnerable Configurations

Part Description Count
Application
Goautodial
2

Exploit-Db

descriptionGoAutoDial 3.3-1406088000 - Multiple Vulnerabilities. CVE-2015-2842,CVE-2015-2843,CVE-2015-2844,CVE-2015-2845. Webapps exploit for php platform
fileexploits/php/webapps/36807.txt
idEDB-ID:36807
last seen2016-02-04
modified2015-04-21
platformphp
port80
published2015-04-21
reporterChris McCurley
sourcehttps://www.exploit-db.com/download/36807/
titleGoAutoDial 3.3-1406088000 - Multiple Vulnerabilities
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/131543/goautodial-execsqlupload.txt
idPACKETSTORM:131543
last seen2016-12-05
published2015-04-21
reporterPacket Storm
sourcehttps://packetstormsecurity.com/files/131543/GoAutoDial-SQL-Injection-Command-Execution-File-Upload.html
titleGoAutoDial SQL Injection / Command Execution / File Upload