Description
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) pidvesa cookie to u5admin/pidvesa.php or (2) uri parameter to u5admin/meta2.php.
Exploits (4)
exploitdb
WORKING POC
by KAhara MAnhara · pythonremotewindows
https://www.exploit-db.com/exploits/36025
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5227.php
Exploit x_refsource_misc
http://packetstormsecurity.com/files/130317/u5CMS-3.9.3-Open-Redirect.html
Scores
EPSS
0.0448
EPSS Percentile
89.2%
Details
Status
published
Products (1)
yuba/u5cms
< 3.9.3
Published
Feb 11, 2015
Tracked Since
Feb 18, 2026