CVE-2015-2842

GoAutoDial GoAdmin CE 3.x - Unauthenticated Arbitrary File Upload via Voice Files Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-2842. PoCs published by Chris McCurley.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in GoAutoDial 3.3, including SQL injection for authentication bypass, arbitrary file upload, and command injection leading to remote code execution (RCE). The PoC includes clear examples of malicious payloads and techniques to achieve RCE and privilege escalation.

Description

Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in sounds/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Chris McCurley · textwebappsphp
https://www.exploit-db.com/exploits/36807

The exploit demonstrates multiple vulnerabilities in GoAutoDial 3.3, including SQL injection for authentication bypass, arbitrary file upload, and command injection leading to remote code execution (RCE). The PoC includes clear examples of malicious payloads and techniques to achieve RCE and privilege escalation.

Classification
Working Poc 100%
Attack Type
Rce | Sqli | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: GoAutoDial 3.3-1406088000 and previous releases
No auth needed
Prerequisites: Network access to the target · Default admin user not removed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535319/100/1100/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74281
Vendor Advisory x_refsource_confirm
http://goautodial.org/news/21
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36807/

Scores

EPSS 0.1316
EPSS Percentile 95.9%

Details

Status published
Products (2)
goautodial/goadmin_ce 3.0
goautodial/goadmin_ce 3.3
Published May 12, 2015
Tracked Since Feb 18, 2026