CVE-2015-5687
Published Oct 5, 2015
Last updated 9 years ago
Overview
- Description
- system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-94
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:anchorcms:anchor_cms:0.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71B5C7B9-E50D-4231-9567-4D53112F4B79" }, { "criteria": "cpe:2.3:a:anchorcms:anchor_cms:0.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E21AA5AA-8F8C-4B60-AD3E-0F74A0E834D4" }, { "criteria": "cpe:2.3:a:anchorcms:anchor_cms:0.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1BC7C9F2-8CEC-49C2-9682-644F202E290C" }, { "criteria": "cpe:2.3:a:anchorcms:anchor_cms:0.9.3:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5CC23692-C05F-4934-8DC7-6F4BE7732A1E" }, { "criteria": "cpe:2.3:a:anchorcms:anchor_cms:0.9.3:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7EE15006-B9CF-4D1C-8B95-C1905E9D4376" } ], "operator": "OR" } ] } ]