Vulnerabilities > CVE-2018-15576 - Deserialization of Untrusted Data vulnerability in Hazzardweb Easylogin PRO
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Exploit-Db
description | Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution. CVE-2018-15576. Remote exploit for PHP platform. Tags: Remote |
file | exploits/php/remote/45227.php |
id | EDB-ID:45227 |
last seen | 2018-08-21 |
modified | 2018-08-20 |
platform | php |
port | |
published | 2018-08-20 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/45227/ |
title | Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution |
type | remote |
Packetstorm
data source | https://packetstormsecurity.com/files/download/149018/easyloginpro130-exec.txt |
id | PACKETSTORM:149018 |
last seen | 2018-08-21 |
published | 2018-08-21 |
reporter | mr_me |
source | https://packetstormsecurity.com/files/149018/Easylogin-Pro-1.3.0-Remote-Code-Execution.html |
title | Easylogin Pro 1.3.0 Remote Code Execution |