CVE-2015-7381

refbase < 0.9.6 - Remote Code Execution via pathToMYSQL or databaseStructureFile Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-7381.

AI-analyzed exploit summary The exploit demonstrates SQL injection and RCE vulnerabilities in Refbase <= 0.9.6 via the 'where' parameter in rss.php and the 'pathToMYSQL' parameter in install.php. It includes functional PoC payloads for SQLi and RCE, with technical details on bypassing input validation.

Description

Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary PHP code via the (1) pathToMYSQL or (2) databaseStructureFile parameter, a different issue than CVE-2015-6008.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/38292

The exploit demonstrates SQL injection and RCE vulnerabilities in Refbase <= 0.9.6 via the 'where' parameter in rss.php and the 'pathToMYSQL' parameter in install.php. It includes functional PoC payloads for SQLi and RCE, with technical details on bypassing input validation.

Classification
Working Poc 100%
Attack Type
Sqli | Rce
Complexity
Trivial
Reliability
Reliable
Target: Refbase <= 0.9.6
No auth needed
Prerequisites: Target must have Refbase <= 0.9.6 installed · For RCE, attacker must know MySQL credentials and target must be Windows
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/374092

Scores

EPSS 0.0320
EPSS Percentile 86.5%

Details

CWE
CWE-94
Status published
Products (1)
refbase/refbase < 0.9.6
Published Sep 28, 2015
Tracked Since Feb 18, 2026