← Back

CVE-2015-7570

nvd nist
Published: Apr 24, 2017Modified: May 13, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.7
Source: NVD

Description

Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adodb_lite.php, libs/org/adodb_lite/tests/test_datadictionary.php, or libs/org/adodb_lite/tests/test_adodb_lite_sessions.php.

Affected (1)

Products: Yeager: Yeager Cms
1 product
Yeager Cms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.2.1

References (8)

Source: secalert@redhat.com
Mailing ListPatchThird Party Advisory
Source: secalert@redhat.com
ExploitPatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party AdvisoryVDB Entry

Timeline

No history available yet.