CVE-2015-1578

u5CMS <3.9.4 - Open Redirect

Title source: llm
STIX 2.1

Description

Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) pidvesa cookie to u5admin/pidvesa.php or (2) uri parameter to u5admin/meta2.php.

Exploits (4)

exploitdb WORKING POC
by KAhara MAnhara · pythonremotewindows
https://www.exploit-db.com/exploits/36025
nomisec WORKING POC
by yaldobaoth · poc
https://github.com/yaldobaoth/CVE-2015-1578-PoC-Metasploit
nomisec WORKING POC
by yaldobaoth · poc
https://github.com/yaldobaoth/CVE-2015-1578-PoC
nomisec WORKING POC
by Zeppperoni · poc
https://github.com/Zeppperoni/CVE-2015-1578

References (2)

Core 2

Scores

EPSS 0.0448
EPSS Percentile 89.2%

Details

Status published
Products (1)
yuba/u5cms < 3.9.3
Published Feb 11, 2015
Tracked Since Feb 18, 2026