CVE-2015-6008: Refbase

High severity, CVSS 7.5. EPSS: 4.8% chance of exploitation in the next 30 days.

install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-2015-7381.

Affected products

  • Refbase Refbase: up to and including 0.9.6

Published 2015-09-28. Last modified 2026-06-17.