Vulnerabilities > CVE-2018-15576 - Deserialization of Untrusted Data vulnerability in Hazzardweb Easylogin PRO

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
hazzardweb
CWE-502
exploit available

Summary

An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionEasylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution. CVE-2018-15576. Remote exploit for PHP platform. Tags: Remote
fileexploits/php/remote/45227.php
idEDB-ID:45227
last seen2018-08-21
modified2018-08-20
platformphp
port
published2018-08-20
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/45227/
titleEasylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
typeremote

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/149018/easyloginpro130-exec.txt
idPACKETSTORM:149018
last seen2018-08-21
published2018-08-21
reportermr_me
sourcehttps://packetstormsecurity.com/files/149018/Easylogin-Pro-1.3.0-Remote-Code-Execution.html
titleEasylogin Pro 1.3.0 Remote Code Execution