Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-1060. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit leverages an authenticated arbitrary file upload vulnerability in AdaptCMS 3.0.3 to upload a malicious PHP file, enabling remote command execution via a web shell. The PoC includes authentication handling and a command execution loop.
Description
Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
Exploits (1)
This exploit leverages an authenticated arbitrary file upload vulnerability in AdaptCMS 3.0.3 to upload a malicious PHP file, enabling remote command execution via a web shell. The PoC includes authentication handling and a command execution loop.