The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2208
Reference (s):
- EXPLOIT-DB:36251
- URL: http://www.exploit-db.com/exploits/36251
- FULLDISC:20150304 PHPMoAdmin Unauthorized Remote Code Execution (0-Day)
- URL: http://seclists.org/fulldisclosure/2015/Mar/19
- http://packetstormsecurity.com/files/130685/PHPMoAdmin-1.1.2-Remote-Code-Execution.html