CVE-2015-2844: Goautodial Goadmin CE
High severity, CVSS 10.0. EPSS: 12.6% chance of exploitation in the next 30 days.
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO.
Affected products
- Goautodial Goadmin CE: version 3.0 only; version 3.3 only
Published 2015-05-12. Last modified 2026-06-17.