Vulnerability Description
Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Insanevisions | Adaptcms | 3.0.3 |
References
- http://osvdb.org/show/osvdb/116721
- http://packetstormsecurity.com/files/129813/AdaptCMS-3.0.3-HTTP-Referer-Header-OExploit
- http://www.exploit-db.com/exploits/35710Exploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5219.phpExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99618
- http://osvdb.org/show/osvdb/116721
- http://packetstormsecurity.com/files/129813/AdaptCMS-3.0.3-HTTP-Referer-Header-OExploit
- http://www.exploit-db.com/exploits/35710Exploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5219.phpExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99618
FAQ
What is CVE-2015-1060?
CVE-2015-1060 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP ...
How severe is CVE-2015-1060?
CVE-2015-1060 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1060?
Check the references section above for vendor advisories and patch information. Affected products include: Insanevisions Adaptcms.