CVE-2018-15576
HIGHEasyLogin Pro < 1.3.0 - Remote Code Execution via Encryptor.php Unserialize
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-15576. PoCs published by mr_me.
AI-analyzed exploit summary This exploit leverages a PHP deserialization vulnerability in Easylogin Pro's Encryptor.php to achieve remote code execution. It crafts a malicious serialized object to write a PHP shell to the target's uploads directory, then triggers it via a reverse shell payload.
Description
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.
Exploits (1)
This exploit leverages a PHP deserialization vulnerability in Easylogin Pro's Encryptor.php to achieve remote code execution. It crafts a malicious serialized object to write a PHP shell to the target's uploads directory, then triggers it via a reverse shell payload.
References (2)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H