CVE-2025-50515 Details
Description
An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the config file was loaded.
A code injection vulnerability has been identified in Empirebak version 2010, specifically within the 'ebak2008/upload/class/config.php' file. This issue arises from the configuration file's handling of double quotes, which can be exploited to inject and execute arbitrary code, such as PHP payloads, when the file is loaded.
Users can close the double quotes in the PHP configuration file to mitigate this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 14, 2025CISA-ADP
Assessed Aug 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Master-0-0/5debd3fbda86edabb1ee80e25c029663 | [email protected] | ExploitTechnical Description |
| https://www.yuque.com/lcc316/df0kgm/bfzpfvb6yaat45nt | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| phome Empirebak 2010 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 15, 2025 | CVE Modified | CISA-ADP |
| Aug 14, 2025 | New CVE Received | [email protected] |
Volerion