Vulnerabilities > CVE-2015-7816 - Unspecified vulnerability in Matomo
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN matomo
nessus
Summary
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HTTP header.
Vulnerable Configurations
Nessus
NASL family | FreeBSD Local Security Checks |
NASL id | FREEBSD_PKG_11351C82990911E5A9C814DAE9D5A9D2.NASL |
description | Piwik changelog reports : This release is rated critical. We are grateful for Security researchers who disclosed security issues privately to the Piwik Security Response team: Elamaran Venkatraman, Egidio Romano and Dmitriy Shcherbatov. The following vulnerabilities were fixed : XSS, CSRF, possible file inclusion in older PHP versions (low impact), possible Object Injection Vulnerability (low impact). |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 87176 |
published | 2015-12-03 |
reporter | This script is Copyright (C) 2015-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/87176 |
title | FreeBSD : piwik -- multiple vulnerabilities (11351c82-9909-11e5-a9c8-14dae9d5a9d2) |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/134220/KIS-2015-10.txt |
id | PACKETSTORM:134220 |
last seen | 2016-12-05 |
published | 2015-11-04 |
reporter | EgiX |
source | https://packetstormsecurity.com/files/134220/Piwik-2.14.3-PHP-Object-Injection.html |
title | Piwik 2.14.3 PHP Object Injection |
References
- http://karmainsecurity.com/KIS-2015-10
- http://karmainsecurity.com/KIS-2015-10
- http://packetstormsecurity.com/files/134220/Piwik-2.14.3-PHP-Object-Injection.html
- http://packetstormsecurity.com/files/134220/Piwik-2.14.3-PHP-Object-Injection.html
- http://seclists.org/fulldisclosure/2015/Nov/15
- http://seclists.org/fulldisclosure/2015/Nov/15
- http://www.securityfocus.com/archive/1/536839/100/0/threaded
- http://www.securityfocus.com/archive/1/536839/100/0/threaded
- https://piwik.org/changelog/piwik-2-15-0/
- https://piwik.org/changelog/piwik-2-15-0/