packetstormsecurity.com
http://packetstormsecurity.com/files/129087/Eleanor-CMS-Open-Redirect.html CVE-2014-9180
Nuclei
Eleanor CMS - Open Redirect
Record summary
CVE-2014-9180 has a selected CVSS score of 5.0; EIP currently links 1 Nuclei template.
Description
Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMEleanor CMS - Open RedirectCVSS 5
Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING.
Impact
Attackers can redirect users to malicious sites for phishing attacks, malware distribution, or credential theft.
Remediation
Update to the latest version of Eleanor CMS to fix the open redirect vulnerability.
WeaknessesCWE-601
AuthorsShankar Acharya
Template tagscve2014cvepacketstormeleanorcmsredirecteleanor-cmsvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:a:eleanor-cms:eleanor_cms:-:*:*:*:*:*:*:*
Shodan: html:"eleanor"
Shodan: http.html:"eleanor"
Shodan: cpe:"cpe:2.3:a:eleanor-cms:eleanor_cms"
FOFA: body="eleanor"
https://packetstormsecurity.com/files/129087/Eleanor-CMS-Open-Redirect.html https://nvd.nist.gov/vuln/detail/CVE-2014-9180
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-9180