Vulnerability Description
PC-EGG pWebManager before 3.3.10, and before 2.2.2 for PHP 4.x, allows remote authenticated users to execute arbitrary OS commands by leveraging the editor role.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pc-Egg | Pwebmanager | <= 3.3.9a |
| Php | Php | 4.4.0 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN25323093/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000180Vendor Advisory
- http://www.pwebmanager.org/PatchVendor Advisory
- http://jvn.jp/en/jp/JVN25323093/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000180Vendor Advisory
- http://www.pwebmanager.org/PatchVendor Advisory
FAQ
What is CVE-2015-7774?
CVE-2015-7774 is a vulnerability with a CVSS score of 6.5 (MEDIUM). PC-EGG pWebManager before 3.3.10, and before 2.2.2 for PHP 4.x, allows remote authenticated users to execute arbitrary OS commands by leveraging the editor role.
How severe is CVE-2015-7774?
CVE-2015-7774 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7774?
Check the references section above for vendor advisories and patch information. Affected products include: Pc-Egg Pwebmanager, Php Php.