Vulnerabilities > CVE-2015-1060 - Unspecified vulnerability in Insanevisions Adaptcms 3.0.3

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
insanevisions
exploit available

Summary

Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header. <a href="http://cwe.mitre.org/data/definitions/601.html">CWE-601: URL Redirection to Untrusted Site ('Open Redirect')</a>

Vulnerable Configurations

Part Description Count
Application
Insanevisions
1

Exploit-Db

descriptionAdaptCMS 3.0.3 - Multiple Vulnerabilities. CVE-2015-1059. Webapps exploit for php platform
fileexploits/php/webapps/35710.py
idEDB-ID:35710
last seen2016-02-04
modified2015-01-06
platformphp
port80
published2015-01-06
reporterLiquidWorm
sourcehttps://www.exploit-db.com/download/35710/
titleAdaptCMS 3.0.3 - Multiple Vulnerabilities
typewebapps