CVE-2015-7381 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.2% (pctl 88)
Patch early
A public exploit exists.
Description
Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary PHP code via the (1) pathToMYSQL or (2) databaseStructureFile parameter, a different issue than CVE-2015-6008.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.2% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-09-28 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| refbase | refbase |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | refbase 0.9.6 - Multiple Vulnerabilities | 2015-09-23 |
→ the Explorer · watch your stack · NVD