CVE-2015-2844: Goautodial Goadmin CE

High severity, CVSS 10.0. EPSS: 12.6% chance of exploitation in the next 30 days.

The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO.

Affected products

  • Goautodial Goadmin CE: version 3.0 only; version 3.3 only

Published 2015-05-12. Last modified 2026-06-17.