Xdebug <= 2.5.5 contains an unauthenticated command injection caused by accepting debugger protocol commands without authentication when remote debugging is enabled, letting remote attackers execute arbitrary PHP code and system commands, exploit requires remote debugging enabled.
id: CVE-2015-10141
info:
name: Xdebug <= 2.5.5 - Command Injection
author: pwnhxl
severity: c
...