CVE-2015-2208 is a critical remote code execution vulnerability affecting phpMoAdmin version 1.1.2. The flaw resides in the saveObject function within moadmin.php, allowing unauthenticated attackers to execute arbitrary commands by injecting shell metacharacters into the object parameter. With a CVSS score of 7.5 and an EPSS percentile of 0.88, this vulnerability poses a significant risk, enabling full compromise of the affected system with low attack complexity. Although not on the KEV catalog, public exploit modules exist, including a Metasploit module and an ExploitDB entry, indicating readily available exploitation tools. Despite the high exploitability, there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.2CPE matchmatch criteria | cpe:2.3:a:avinu:phpmoadmin:1.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.