---
cve: "CVE-2015-5243"
severity: "LOW"
cvss: 3.1
epss: "6.2%"
vendor: "n/a"
kev: false
exploited: false
published: "2018-08-20 21:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T13:16:32+02:00"
---

# CVE-2015-5243

> 3.1 LOW · 🧪 PoC

## Beschreibung

phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.

## Referenzen

- <https://github.com/jsmitty12/phpWhois/issues/19>
- <https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180425-01_phpWhois_Code_Execution>
- <https://github.com/sparc/phpWhois.org/commit/5cc572490c9053d46598ec9348a11e36a5a33a46#diff-f150ae17da7341bf6c2eff928684b3a3>
- <https://github.com/Gemorroj/phpwhois/commit/91c937e03c876ba1290b6de2a3ad953d2105fdd0>
- <https://blog.nettitude.com/uk/cve-2015-5243-phpwhois-remote-code-execution>
- <https://github.com/jsmitty12/phpWhois/blob/master/CHANGELOG.md>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-5243) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
