Vulnerabilities > CVE-2018-15576 - Deserialization of Untrusted Data vulnerability in Hazzardweb Easylogin PRO

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
hazzardweb
CWE-502
exploit available

Summary

An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionEasylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution. CVE-2018-15576. Remote exploit for PHP platform. Tags: Remote
fileexploits/php/remote/45227.php
idEDB-ID:45227
last seen2018-08-21
modified2018-08-20
platformphp
port
published2018-08-20
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/45227/
titleEasylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
typeremote

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/149018/easyloginpro130-exec.txt
idPACKETSTORM:149018
last seen2018-08-21
published2018-08-21
reportermr_me
sourcehttps://packetstormsecurity.com/files/149018/Easylogin-Pro-1.3.0-Remote-Code-Execution.html
titleEasylogin Pro 1.3.0 Remote Code Execution