CVE-2015-7904

Infinite Automation Mango Automation <2.6.0 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-7904. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit demonstrates a CSRF-based file upload vulnerability in Mango Automation 2.6.0, allowing arbitrary JSP code execution by uploading a malicious JSP file. It also includes additional vulnerabilities like arbitrary command execution, debug log exposure, and SQL injection.

Description

Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsjsp
https://www.exploit-db.com/exploits/38338

The exploit demonstrates a CSRF-based file upload vulnerability in Mango Automation 2.6.0, allowing arbitrary JSP code execution by uploading a malicious JSP file. It also includes additional vulnerabilities like arbitrary command execution, debug log exposure, and SQL injection.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mango Automation 2.5.2 and 2.6.0 beta (build 327)
Auth required
Prerequisites: Authenticated session · Access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Patch, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-15-300-02

Scores

EPSS 0.0278
EPSS Percentile 84.5%

Details

Status published
Products (3)
infinite_automation_systems/mango_automation 2.5.0
infinite_automation_systems/mango_automation 2.5.5
infinite_automation_systems/mango_automation 2.6.0
Published Oct 28, 2015
Tracked Since Feb 18, 2026