Record summary

CVE-2016-0957 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHAdobe AEM Dispatcher <4.15 - Rules BypassCVSS 7.5

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

Impact

The vulnerability allows attackers to bypass security rules and potentially gain unauthorized access to sensitive information or perform malicious actions.

Remediation

Upgrade to Adobe AEM Dispatcher version 4.15 or higher to fix the vulnerability.

Authorsgeeknik
Template tagscve2016cveadobeaemvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:adobe:dispatcher:*:*:*:*:*:*:*:*
Shodan: http.component:"Adobe Experience Manager"
Shodan: http.component:"adobe experience manager"

Source: ProjectDiscovery

References

2