CVE-2017-15579

CRITICAL

php_melody < 2.7.3 - SQL Injection via aa_pages_per_page Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-15579. PoCs published by SecuriTeam.

AI-analyzed exploit summary The document describes three vulnerabilities in PHP Melody 2.7.3: a stored XSS leading to admin account takeover, and two SQL injection flaws (one in POST parameter and another in a cookie value). It includes payload examples but lacks executable exploit code.

Description

In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.

Exploits (1)

exploitdb WRITEUP
by SecuriTeam · webappsphp
https://www.exploit-db.com/exploits/44056

The document describes three vulnerabilities in PHP Melody 2.7.3: a stored XSS leading to admin account takeover, and two SQL injection flaws (one in POST parameter and another in a cookie value). It includes payload examples but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Xss | Sqli
Complexity
Moderate
Reliability
Theoretical
Target: PHP Melody 2.7.3
No auth needed
Prerequisites: Access to vulnerable PHP Melody instance · Admin interaction for XSS payload execution
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
http://www.phpsugar.com/blog/2017/10/php-melody-v2-7-3-maintenance-release/
Exploit, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/3464

Scores

CVSS v3 9.8
EPSS 0.0149
EPSS Percentile 70.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
phpsugar/php_melody < 2.7.2
Published Oct 18, 2017
Tracked Since Feb 18, 2026