CVE-2011-5252
NUCLEIOrchard 1.0.x-1.0.20, 1.1.x-1.1.30, 1.2.x-1.2.41, 1.3.x-1.3.9 - Open Redirect via ReturnUrl Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-5252. PoCs published by Mesut Timur. A Nuclei detection template is also available.
AI-analyzed exploit summary The provided text describes a URI-redirection vulnerability in Orchard CMS version 1.3.9, where unsanitized user input in the 'ReturnUrl' parameter can be exploited for phishing or other attacks. It includes a proof-of-concept URL demonstrating the issue.
Description
Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.
Exploits (1)
The provided text describes a URI-redirection vulnerability in Orchard CMS version 1.3.9, where unsanitized user input in the 'ReturnUrl' parameter can be exploited for phishing or other attacks. It includes a proof-of-concept URL demonstrating the issue.