CVE-2015-4118
Ispconfig < 3.0.5.4 - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.
Exploits (1)
References (6)
Scores
EPSS
0.0191
EPSS Percentile
83.1%
Classification
CWE
CWE-89
Status
draft
Affected Products (1)
ispconfig/ispconfig
< 3.0.5.4
Timeline
Published
Jun 15, 2015
Tracked Since
Feb 18, 2026