VulnerabilityModified
CVE-2014-8731
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.
CRITICAL 9.8EPSS 11.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.76% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- phpmemcachedadmin project/phpmemcachedadmin
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/129089/PHPMemcachedAdmin-1.2.2-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/533968/100/0/threaded
- http://www.securityfocus.com/archive/1/533980/100/0/threaded
- http://www.securityfocus.com/bid/71059Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98638
- http://packetstormsecurity.com/files/129089/PHPMemcachedAdmin-1.2.2-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/533968/100/0/threaded
- http://www.securityfocus.com/archive/1/533980/100/0/threaded
- http://www.securityfocus.com/bid/71059Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98638
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.