Vulnerabilities > CVE-2018-15576 - Deserialization of Untrusted Data vulnerability in Hazzardweb Easylogin PRO
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Exploit-Db
description | Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution. CVE-2018-15576. Remote exploit for PHP platform. Tags: Remote |
file | exploits/php/remote/45227.php |
id | EDB-ID:45227 |
last seen | 2018-08-21 |
modified | 2018-08-20 |
platform | php |
port | |
published | 2018-08-20 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/45227/ |
title | Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution |
type | remote |
Packetstorm
data source | https://packetstormsecurity.com/files/download/149018/easyloginpro130-exec.txt |
id | PACKETSTORM:149018 |
last seen | 2018-08-21 |
published | 2018-08-21 |
reporter | mr_me |
source | https://packetstormsecurity.com/files/149018/Easylogin-Pro-1.3.0-Remote-Code-Execution.html |
title | Easylogin Pro 1.3.0 Remote Code Execution |